{"id":3955,"date":"2013-05-14T19:24:27","date_gmt":"2013-05-14T23:24:27","guid":{"rendered":"http:\/\/www.hostdime.com\/blog\/?p=3955"},"modified":"2014-12-11T13:40:38","modified_gmt":"2014-12-11T18:40:38","slug":"hostdime-notice-of-centos-6-vulnerability","status":"publish","type":"post","link":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/","title":{"rendered":"HostDime Notice of CentOS 6 Vulnerability"},"content":{"rendered":"<p>It has come to our attention that there is a Linux local root exploit making the rounds. This exploit uses a previously unannounced vulnerability in the Kernel relating to the performance counter subsystem in order to escalate privileges to root. Because this system is a recent advancement in the kernel, only CentOS 6 should be impacted by this vulnerability.<\/p>\n<p>Due to the nature of the disclosure, RedHat has not had sufficient time to release a patched kernel. Once that is done and CentOS picks up the new kernel from the upstream, we will be able to upgrade your kernel and fix the vulnerability. In the meantime we are pushing a change to the kernel parameters which will help prevent the exploit from succeeding in its original state. This in NO WAY fixes the vulnerability and your kernel will still need to be updated as soon as possible. Again, this change is not a fix and your kernel is STILL vulnerable until RedHat\/CentOS release a patched kernel. In the meantime, we also recommend the following practices are also followed to help reduce the likelihood of a successful exploit:<\/p>\n<p>1) Ensure nobody has shell access to your server unless absolutely necessary and even then, it should only ever be in a jailed shell. In this circumstance, jailed shell provides no extra protection, but it does in others.<br \/>\n2) Ensure all web applications hosted on the server are up to date<br \/>\n3) On WHM servers you should disable access to compilers through &#8216;Main &gt;&gt; Security Center &gt;&gt; Compiler Access&#8217;. The end goal is to prevent access to the system compiler for non privileged users. So on any non cPanel systems, simply removing all &#8216;other&#8217; permissions from all compilation tools will also suffice.<\/p>\n<p>For clients running cPanel version 11.34 and lower, you will follow the steps in the email exactly and turn \u201cCompilers Tweak\u201d on. This will stop access to the C Compiler for underprivileged users, thus ensuring the exploit cannot be used.<\/p>\n<p>For clients running cPanel version 11.36 or higher, the utility \u201cCompilers Tweak\u201d has been changed to the new utility \u201cCompiler Access\u201d. This new tool allows you to give access to underprivileged users if you desire. To avoid issues with this vulnerability, you want to ensure that \u201cCompiler Access\u201d is disabled.<\/p>\n<p>Once a new kernel is released, we will be notifying impacted clients regarding updating the kernel. As always, if there are any questions, please do not hesitate to <a href=\"http:\/\/core.hostdime.com\" target=\"_blank\">open up a ticket<\/a> with our support department and they will be more than happy to assist you further.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>It has come to our attention that there is a Linux local root exploit making the rounds.<\/p>\n","protected":false},"author":13,"featured_media":7534,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-3955","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-misc"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>HostDime Notice of CentOS 6 Vulnerability<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HostDime Notice of CentOS 6 Vulnerability\" \/>\n<meta property=\"og:description\" content=\"It has come to our attention that there is a Linux local root exploit making the rounds.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"HostDime Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/hostdime\" \/>\n<meta property=\"article:published_time\" content=\"2013-05-14T23:24:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2014-12-11T18:40:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2013\/05\/alert.png\" \/>\n\t<meta property=\"og:image:width\" content=\"500\" \/>\n\t<meta property=\"og:image:height\" content=\"364\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Jared Smith\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jared Smith\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/\"},\"author\":{\"name\":\"Jared Smith\",\"@id\":\"https:\/\/www.hostdime.com\/blog\/#\/schema\/person\/fdc19f9386316cd19f8eebb64a223503\"},\"headline\":\"HostDime Notice of CentOS 6 Vulnerability\",\"datePublished\":\"2013-05-14T23:24:27+00:00\",\"dateModified\":\"2014-12-11T18:40:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/\"},\"wordCount\":428,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.hostdime.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2013\/05\/alert.png\",\"articleSection\":[\"Misc\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/\",\"url\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/\",\"name\":\"HostDime Notice of CentOS 6 Vulnerability\",\"isPartOf\":{\"@id\":\"https:\/\/www.hostdime.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2013\/05\/alert.png\",\"datePublished\":\"2013-05-14T23:24:27+00:00\",\"dateModified\":\"2014-12-11T18:40:38+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#primaryimage\",\"url\":\"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2013\/05\/alert.png\",\"contentUrl\":\"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2013\/05\/alert.png\",\"width\":500,\"height\":364},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.hostdime.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HostDime Notice of CentOS 6 Vulnerability\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.hostdime.com\/blog\/#website\",\"url\":\"https:\/\/www.hostdime.com\/blog\/\",\"name\":\"HostDime Data Center Blog\",\"description\":\"Hyper Edge, Purpose-Built Data Centers\",\"publisher\":{\"@id\":\"https:\/\/www.hostdime.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.hostdime.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.hostdime.com\/blog\/#organization\",\"name\":\"HostDime\",\"url\":\"https:\/\/www.hostdime.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.hostdime.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2019\/04\/pldooampldeadoii.png\",\"contentUrl\":\"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2019\/04\/pldooampldeadoii.png\",\"width\":150,\"height\":150,\"caption\":\"HostDime\"},\"image\":{\"@id\":\"https:\/\/www.hostdime.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/hostdime\",\"https:\/\/x.com\/hostdime\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.hostdime.com\/blog\/#\/schema\/person\/fdc19f9386316cd19f8eebb64a223503\",\"name\":\"Jared Smith\",\"description\":\"Jared Smith is HostDime's Director of Marketing and the author of the HostDime Blog. Email Jared for guest blogging opportunities on your website or this one.\",\"sameAs\":[\"http:\/\/hostdime.com\/blog\"],\"url\":\"https:\/\/www.hostdime.com\/blog\/author\/jared-s\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HostDime Notice of CentOS 6 Vulnerability","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/","og_locale":"en_US","og_type":"article","og_title":"HostDime Notice of CentOS 6 Vulnerability","og_description":"It has come to our attention that there is a Linux local root exploit making the rounds.","og_url":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/","og_site_name":"HostDime Blog","article_publisher":"https:\/\/www.facebook.com\/hostdime","article_published_time":"2013-05-14T23:24:27+00:00","article_modified_time":"2014-12-11T18:40:38+00:00","og_image":[{"width":500,"height":364,"url":"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2013\/05\/alert.png","type":"image\/png"}],"author":"Jared Smith","twitter_misc":{"Written by":"Jared Smith","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#article","isPartOf":{"@id":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/"},"author":{"name":"Jared Smith","@id":"https:\/\/www.hostdime.com\/blog\/#\/schema\/person\/fdc19f9386316cd19f8eebb64a223503"},"headline":"HostDime Notice of CentOS 6 Vulnerability","datePublished":"2013-05-14T23:24:27+00:00","dateModified":"2014-12-11T18:40:38+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/"},"wordCount":428,"commentCount":0,"publisher":{"@id":"https:\/\/www.hostdime.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2013\/05\/alert.png","articleSection":["Misc"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/","url":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/","name":"HostDime Notice of CentOS 6 Vulnerability","isPartOf":{"@id":"https:\/\/www.hostdime.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#primaryimage"},"image":{"@id":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2013\/05\/alert.png","datePublished":"2013-05-14T23:24:27+00:00","dateModified":"2014-12-11T18:40:38+00:00","breadcrumb":{"@id":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#primaryimage","url":"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2013\/05\/alert.png","contentUrl":"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2013\/05\/alert.png","width":500,"height":364},{"@type":"BreadcrumbList","@id":"https:\/\/www.hostdime.com\/blog\/hostdime-notice-of-centos-6-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hostdime.com\/blog\/"},{"@type":"ListItem","position":2,"name":"HostDime Notice of CentOS 6 Vulnerability"}]},{"@type":"WebSite","@id":"https:\/\/www.hostdime.com\/blog\/#website","url":"https:\/\/www.hostdime.com\/blog\/","name":"HostDime Data Center Blog","description":"Hyper Edge, Purpose-Built Data Centers","publisher":{"@id":"https:\/\/www.hostdime.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hostdime.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hostdime.com\/blog\/#organization","name":"HostDime","url":"https:\/\/www.hostdime.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hostdime.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2019\/04\/pldooampldeadoii.png","contentUrl":"https:\/\/www.hostdime.com\/blog\/wp-content\/uploads\/2019\/04\/pldooampldeadoii.png","width":150,"height":150,"caption":"HostDime"},"image":{"@id":"https:\/\/www.hostdime.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/hostdime","https:\/\/x.com\/hostdime"]},{"@type":"Person","@id":"https:\/\/www.hostdime.com\/blog\/#\/schema\/person\/fdc19f9386316cd19f8eebb64a223503","name":"Jared Smith","description":"Jared Smith is HostDime's Director of Marketing and the author of the HostDime Blog. Email Jared for guest blogging opportunities on your website or this one.","sameAs":["http:\/\/hostdime.com\/blog"],"url":"https:\/\/www.hostdime.com\/blog\/author\/jared-s\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/posts\/3955","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/comments?post=3955"}],"version-history":[{"count":1,"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/posts\/3955\/revisions"}],"predecessor-version":[{"id":7535,"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/posts\/3955\/revisions\/7535"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/media\/7534"}],"wp:attachment":[{"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/media?parent=3955"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/categories?post=3955"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hostdime.com\/blog\/wp-json\/wp\/v2\/tags?post=3955"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}