Tag: technical-blog

Now supporting mod_lsapi for Nginx

Now supporting mod_lsapi for Nginx

This update introduces comprehensive support for the mod_lsapi module with NGINX, marking a significant enhancement in the efficiency and functionality of NGINX servers utilizing LSAPI. This integration not only broadens the capabilities of NGINX servers but also ensures compatibility with key features and the stability of hosted applications. Here's what's new:

CloudLinux ELevate: Stable Version Now Released. Simplified Transitioning from CloudLinux 7 to 8

 

CloudLinux ELevate: Stable Version Now Released

CloudLinux proudly announces the stable release of ELevate, making it easier for users to transition from CloudLinux 7 to CloudLinux 8. With enhanced features and refinements, ELevate ensures a smooth migration journey for hosting providers. Learn more about ELevate here.

Note: Even after the stable release, ELevate represents a significant alteration to the operating system's structure and carries potential risks. Therefore, making a full server backup before initiating the ELevate process is crucial to ensure the server's recovery and functionality should any issues arise.

CVE-2024-1086 Vulnerability - Mitigation for CloudLinux OS servers

CL20241086b

A new vulnerability was discovered in the Netfilter subsystem in the Linux kernel identified as CVE-2024-1086. The CloudLinux team is actively working to address and mitigate the security issue within our software.


*Please note: An update for April 3, 2024, has been added to the end of this post

CloudLinux Now Offers Seamless Switching Between Editions

seamless_switch2

CloudLinux has made transitioning between editions smoother than ever. With all license editions unified under a single software package, customers can easily switch licenses and activate new features. Now, users can seamlessly move from CL Solo to CL Admin/Shared/Shared PRO, regardless of LVE support, and explore multiple transition paths for greater flexibility and choice.

Technical Update: Deprecation of Percona Support

percona_EOL

Due to the limited interest in Percona demonstrated by usage data, the decision was made to cease further updates of Percona starting from March 13th.

 

Tech Update: CloudLinux 9 and cPanel 118 Integration Now Stable for Production

CloudLinux 9 and cPanel 118 Integration
The CloudLinux OS team is pleased to announce that CL9 + cPanel is now ready for production use. After eagerly awaiting the stable release of cPanel version 118, we can now officially confirm its availability. For detailed information on supported operating systems for cPanel, check out the official documentation here.

 

Navigating Change: CloudLinux 6/7 End-of-Life and Migration Strategies

CloudLinux 6/7 End-of-Life

Effective July 1st, 2024, CloudLinux 6 and 7 will reach End of Life (EOL). Routine updates and support will cease, but critical CVE support for issues with a severity score of 8 or higher will continue until July 1st, 2025. This extension allows administrators additional time to plan migrations.

Additionally, the repositories will remain available with the frozen versions of packages until March 1st, 2029.

RESOLVED! Gradual rollout for lve-stats, lve-utils, cagefs paused

rolloutpaused

Update as of Jan 12, 2024:

We would like to inform you that the gradual rollout of the rollout slot-5 was successfully unpaused, and bugfix for incorrect permissions being set for files created by lve-stats was fixed in the version lve-stats #4.2.5-1.

 

We would like to inform you that the gradual rollout of the rollout slot-5 was paused due to incorrect permissions being set for files created by lve-stats (e.g. /var/lve/info).

Cldeploy script updated

cldeploy-script

A new updated cldeploy script version v1.102 is now available for download from the CloudLinux repository https://repo.cloudlinux.com/cloudlinux/sources/cln/cldeploy.

CVE-2023-4863 Security Vulnerability: CloudLinux Takes Action - Mitigation for CloudLinux OS Servers

CL_CVE-2023-4863 Security Vulnerability_V1 copy

A newly discovered critical WebP 0-day security vulnerability, identified as CVE-2023-4863, CloudLinux OS team We are actively addressing and mitigating the security issue within our software. 

 

To summarize the impact on different CloudLinux versions:

  • CloudLinux 7: No vulnerability found.
  • CloudLinux 8: Fixed version is libwebp-1.0.0-8.el8_8.1, please update your OS to this version.
  • CloudLinux 9: Fixed version is libwebp-1.2.0-7.el9_2, please update your OS to this version.

imunify-logo

WEB SERVER SECURITY BLOG

Subscribe to CloudLinux Newsletter