Announcement

Collapse
No announcement yet.

CVE-2014-0196 vulnerability update

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • CVE-2014-0196 vulnerability update

    In the post:


    It is mentioned that the fix has just been pushed via kernel care and there are no kernel updates and this is still being investigated if it affects cloudlinux.

    Redhat has pushed out fixes for their kernels:


    I have a few queries in this regards:
    When will we get the kernel update to fix this issue or has it been pushed?
    Is the only way to get this right now is via kernelcare?
    Does it not affect the cloudlinux kernel version 2.6.32-458.6.2 onwards since it is based on the red hat kernel?

    -- Ayush

  • #2
    The RHEL / CentOS kernels before 2.6.32-358.6.1.el6, openvz kernels before 042stab078.1 and CL kernels before 2.6.32-458.6.2 are all vulnerable to this exploit.
    any newer kernels are not vulnerable.

    While this patch might still make it in the future versions of kernel -- it is just going to be a bug fix, not a security fix any more.

    Comment

    Working...
    X