Kernel: "Copy Fail", "Dirty Frag" & "GhostLock" CVEs patched

Addendum

Please note that CloudLinux/Imunify engineers are currently investigating 2x instances of I/O runaway leading to overload into kernel taint, which appears potentially related to the GhostLock patch interacting with Imunify360.

We’re keeping a close eye on operations today, as there was a 2nd instance of this on another machine today with only some of the hallmarks from the 1st instance of it last night. At least 1 more update will be provided.

Edit: Further updates via separate advisory https://the.uptime.business/issues/6a5dfc042b0e94e98e847d0d

Addendum

Please note we’ve upgraded all CloudLinux kernels to 4.18.0-553.141.2.lve.el8.x86_64 to patch:

Addendum

We’re slowly testing & rolling out Kernel 4.18.0-553.141.2.lve.el8.x86_64 to patch “GhostLock”.

As this is currently in CloudLinux’s testing release channel we’re ensuring stability through corporate firstly.

Information

G’day,

Please note we’ve upgraded CloudLinux kernels to 4.18.0-553.123.2.lve.el8.x86_64 to patch both:

The upgraded kernels (in runtime via reboot) now take over from KernelCare live patching updates before.

We’ve waited until these were pushed to stable and not subsequently revoked, which is now the case.

Please let us know if you’ve any concerns with regard to these security upgrades and reboots.

Now we’re in the AI era (look up “Project Glasswing” etc), expect more CVEs to drop soon.

Cheers,
Merlot Digital

3 Affected Services:
The Network Crew Pty Ltd (TNC)

« Merlot Digital website «

Network: AS138521