• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Issue Can kernel be updated in Centos without breaking Plesk.

Paul Larson

Basic Pleskian
A Centos/Plesk server of ours failed a PCI compliance test. The vulnerability cites a Linux 4.4 kernel, yet I'm running 3.1.

Server Details:
  • CentOS Linux release 7.8.2003 (Core)
  • 18.0.29.3 Plesk Obsidian 18.0
  • CentOS Linux release 7.8.2003 (Core)

Derived from Red Hat Enterprise Linux 7.8 (Source)


NAME="CentOS Linux"

Question: Could I update the kernel to a 4.4+ version w/o breaking Plesk?

I see no way to remediate the CVE without updating the kernel.

I found this HowTo for updating the Kernel within CentOs, but not sure if this could harm Plesk.


PCI Failure details
CVE Title:
CPE Based Vulnerabilities for Linux 4.4
Impact:
One or more vulnerabilities have been found that affect this service. Please see the relevant CVEs for more details.

Resolution:
Apply the latest vendor patches to your operating system: Linux 4.4

Summary

7.1

CVE Score
CVE-2018-10938 7.1
CVE-2016-2143 6.9
CVE-2016-2854 4.6
CVE-2017-7273 4.6
CVE-2016-2853 4.4
 

Attachments

  • Screen Shot 2020-09-10 at 9.19.29 AM.png
    Screen Shot 2020-09-10 at 9.19.29 AM.png
    124.4 KB · Views: 4
If you are updating the kernel from the official OS vendor repository, then it is safe for Plesk.
 
Back
Top