• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Issue Can kernel be updated in Centos without breaking Plesk.

Paul Larson

Basic Pleskian
A Centos/Plesk server of ours failed a PCI compliance test. The vulnerability cites a Linux 4.4 kernel, yet I'm running 3.1.

Server Details:
  • CentOS Linux release 7.8.2003 (Core)
  • 18.0.29.3 Plesk Obsidian 18.0
  • CentOS Linux release 7.8.2003 (Core)

Derived from Red Hat Enterprise Linux 7.8 (Source)


NAME="CentOS Linux"

Question: Could I update the kernel to a 4.4+ version w/o breaking Plesk?

I see no way to remediate the CVE without updating the kernel.

I found this HowTo for updating the Kernel within CentOs, but not sure if this could harm Plesk.


PCI Failure details
CVE Title:
CPE Based Vulnerabilities for Linux 4.4
Impact:
One or more vulnerabilities have been found that affect this service. Please see the relevant CVEs for more details.

Resolution:
Apply the latest vendor patches to your operating system: Linux 4.4

Summary

7.1

CVE Score
CVE-2018-10938 7.1
CVE-2016-2143 6.9
CVE-2016-2854 4.6
CVE-2017-7273 4.6
CVE-2016-2853 4.4
 

Attachments

  • Screen Shot 2020-09-10 at 9.19.29 AM.png
    Screen Shot 2020-09-10 at 9.19.29 AM.png
    124.4 KB · Views: 4
If you are updating the kernel from the official OS vendor repository, then it is safe for Plesk.
 
Back
Top