---
title: KernelCare Blog - News and Articles about Live Patching Technology | Vulnerability fix
description: Vulnerability fix | Learn more about Live Patching technology from KernelCare Blog.
---

We are updating the structure and design of KernelCare blog for your convenience. Today, you may experience some text formatting inconvenience which will be fixed shortly.

[![](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-1.png)](https://www.kernelcare.com/contact/)[Contact Sales](https://www.kernelcare.com/contact/) [![](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-2.png) Login to CLN](https://cln.cloudlinux.com/console/auth/login?originUrl=%2Fdashboard%2Fproducts)

[![](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-3.png) Customer Support](https://cloudlinux.zendesk.com/hc/en-us/requests/new)

[![](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-4.png) About ![](https://www.kernelcare.com/wp-content/uploads/2019/09/arrow.png)](https://www.kernelcare.com/about/)

[About KernelCare](https://www.kernelcare.com/about/)

[Contact us](https://www.kernelcare.com/contact/)

[Management team](https://www.kernelcare.com/about/#the-team)

[Privacy](https://www.kernelcare.com/legal-agreements-for-kernelcare/)

[![kernelcare white and blue](https://www.kernelcare.com/wp-content/uploads/2019/09/kernelcare-white-and-blue.png)](https://www.kernelcare.com)

- [![kernelcare white](https://www.kernelcare.com/wp-content/uploads/2019/09/kernelcare-white-193x40.png)](https://www.kernelcare.com/)
- [Products](https://www.kernelcare.com/product/) 
    - - - [Supported distributions & kernels](https://www.kernelcare.com/supported-distributions-and-kernels/)
                  - [Compare KernelCare with other live patching tools](https://tuxcare.com/compare-live-patching-tools/)
                  - [Switch from Ksplice to KernelCare without a reboot](https://www.kernelcare.com/switching-from-ksplice-to-kernelcare-free-trial/) POPULAR
          - - [![](https://www.kernelcare.com/wp-content/uploads/kernelcare-plus-new.webp)](https://tuxcare.com/live-patching-services/librarycare/)
                    
                     Live patching for Linux kernels, OpenSSL & glibc.  
                     Perfect for medium & large enterprise companies (500+ servers)
                    
                    [Start a trial or purchase](https://tuxcare.com/live-patching-services/librarycare/)
                  - [![](https://www.kernelcare.com/wp-content/uploads/kernelcare-enterprise.webp)](https://tuxcare.com/live-patching-services/kernelcare-enterprise/)NEW
                    
                     KernelCare with out-of-the-box integration with automation tools & vulnerability scanners, priority support and separate ePortal server Specially tailored for companies with 1000+ servers
                    
                    [Get a quote](https://tuxcare.com/live-patching-services/kernelcare-enterprise/)
          - - [![](https://www.kernelcare.com/wp-content/uploads/kernelcare-black-and-blue.webp)](https://tuxcare.com/live-patching-services/)
                    
                     Essential functions of automated Live patching for Linux kernels.   
                     Perfect for hosting providers and small enterprise (up to 500 servers)
                    
                    [Start a trial or purchase](https://tuxcare.com/live-patching-services/)
                  - [![](https://www.kernelcare.com/wp-content/uploads/kernelcare_iot.webp)](https://tuxcare.com/live-patching-services/kernelcare-iot/)
                    
                     Live patching for Linux kernels in Arm-based devices.  
                     Custom patching set up solely for your embedded infrastructure
                    
                    [Apply for a free POC](https://tuxcare.com/live-patching-services/kernelcare-iot/)
    - - - [Supported distributions & kernels](https://www.kernelcare.com/supported-distributions-and-kernels/)
                  - [Compare KernelCare with other live patching tools](https://tuxcare.com/compare-live-patching-tools/)
                  - [Switch from Ksplice to KernelCare without a reboot](https://www.kernelcare.com/switching-from-ksplice-to-kernelcare-free-trial/) POPULAR
- [Pricing](https://www.kernelcare.com/pricing/)
- [Resources](https://www.kernelcare.com/resource/) 
    - - - Education & News
                  - [Blog](https://blog.kernelcare.com/)
                  - [FAQ](https://www.kernelcare.com/faqs/)
                  - [eBooks & Whitepapers](https://www.kernelcare.com/category/resources/whitepaper/)
                  - [Events & Webinars](https://www.kernelcare.com/category/resources/webinars/)
                  - [All Resources](https://www.kernelcare.com/resource/)
          - - [Support](https://www.kernelcare.com/support/)
                  - [Forum](https://cloudlinux.zendesk.com/hc/en-us/community/topics/360001034619-KernelCare-General-Discussion)
                  - [Customer Support](https://cloudlinux.zendesk.com/hc/en-us/requests/new)
                  - [Pre-sale support](https://www.kernelcare.com/contact/)
                  - [Marketing enquiries](mailto:marketing@cloudlinux.com)
          - - [Documentation](https://docs.kernelcare.com/)
                  - [How to install KernelCare](https://www.kernelcare.com/how-to-install-kernelcare/)
                  - [Patch Notifications](https://www.kernelcare.com/patch-notifications/)
                  - [KernelCare Patches](https://patches.kernelcare.com/#All%20Kernels#)
                  - [Changelog](https://blog.kernelcare.com/tag/changelog)
                  - [Full Documentation](https://docs.kernelcare.com/)
- [Blog](https://blog.kernelcare.com/)
- [Get KernelCare Free](https://tuxcare.com/live-patching-services/)
- [![](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-1.png) Contact Sales](https://www.kernelcare.com/contact/) [![](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-3.png) Customer Support](https://cloudlinux.zendesk.com/hc/en-us/requests/new)
  
  [![](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-2.png) Login to CLN](https://cln.cloudlinux.com/console/auth/login?originUrl=%2Fdashboard%2Fproducts)

- [![kernelcare white](https://www.kernelcare.com/wp-content/uploads/kernelcare-black-and-blue.webp)](https://www.kernelcare.com/)
- [Blog](https://blog.kernelcare.com/)
- [Enterprise Security](https://blog.kernelcare.com/tag/kernelcare-enterprise)
- [IoT Security](https://blog.kernelcare.com/tag/iot)
- [Userspace Patching](https://blog.kernelcare.com/tag/kernelcareplus)
- [Get KernelCare Free](https://www.kernelcare.com/free-trial/)
- Subscribe
- ![](https://blog.kernelcare.com/hubfs/search-icon.png)

# [How to Upgrade An Unsupported OS: An In-depth Checklist](https://blog.kernelcare.com/tutorial/how-to-upgrade-an-unsupported-os-an-in-depth-checklist)

[Read More](https://blog.kernelcare.com/tutorial/how-to-upgrade-an-unsupported-os-an-in-depth-checklist)

 Tag: vulnerability-fix

## [BPF code can allow local privilege escalation (CVE-2021-29154)](https://blog.kernelcare.com/vulnerability/specially-crafted-bpf-code-can-allow-local-privilege-escalation-cve-2021-29154)

 Apr 12, 2021, 1:18:00 PM

![Another vulnerability targeting the BPF subsystem has been disclosed publicly in the past few days (CVE-2021-29154). It allows users on a system running non-default configuration of the BPF subsystem to run specially crafted code as a BPF filter and run arbitrary executable code in the kernel context.   According to vendors, it affects all distributions running kernels up to version 5.11.12. Distribution vendors are starting to deliver patches through their update mechanisms, and KernelCare is also finalizing patches for it’s rebootless patching process to address this issue.  Because of the nature of the BPF functionality, which is to allow user code to interact with network packet processing within the kernel, there is a very big potential for attack given any weakness in the implementation. This specific functionality has been addressed recently in the specter mitigation code bug discussed here.  To be vulnerable, a system would have to be configured to allow BPF JIT compilation (for example, by setting “net.core.bpf_jit_enable = 1”). This is often the case in situations where regular users are doing work related to sockets’ manipulation or in seccomp (secure computing mode) environments where permissions are granted more granularly than normal.  The actual vulnerable code resides in arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c in the kernel source code tree. The flaw comes from the way branch displacement happens when the user code is compiled, by making wrong assumptions regarding the address of code during optimization.  Proper exploitation of this vulnerability could even lead to container or chroots’ escape, since the kernel is shared between them, and running code in the kernel context permits it to escape containerization limits.  As a stop-gap procedure, you can quickly disable BPF JIT by running:  # echo 0 > /proc/sys/net/core/bpf_jit_enable   Which will persist until reversed or a system reboot. A more permanent removal can be achieved by using your distribution’s syscfg equivalent utility to set “net.core.bpf_jit_enable=0” at boot time. Of course, this type of solution solves the problem by disabling the functionality, which in itself is self-defeating. If you actually had your system configured to use BPF JIT, in all likelihood your use case needed that setting explicitly enabled, and you should rely instead on proper kernel patching, either through your distribution vendor’s patches or through KernelCare’s rebootless process.](https://blog.kernelcare.com/hs-fs/hubfs/apr%2012%20compressed.jpeg?width=2600&name=apr%2012%20compressed.jpeg)

Another vulnerability targeting the BPF subsystem has been disclosed publicly in the past few days ([CVE-2021-29154](https://nvd.nist.gov/vuln/detail/CVE-2021-29154)). It allows users on a system running non-default configuration of the BPF subsystem to run specially crafted code as a BPF filter and run arbitrary executable code in the kernel context. 

 

According to vendors, it affects all distributions running kernels up to version 5.11.12. Distribution vendors are starting to deliver patches through their update mechanisms, and KernelCare is also finalizing patches for it’s rebootless patching process to address this issue.

[Read More](https://blog.kernelcare.com/vulnerability/specially-crafted-bpf-code-can-allow-local-privilege-escalation-cve-2021-29154)

[![](https://blog.kernelcare.com/hubfs/apr%2012%20compressed.jpeg)](https://blog.kernelcare.com/vulnerability/specially-crafted-bpf-code-can-allow-local-privilege-escalation-cve-2021-29154)

## [Two more vulnerabilities uncovered in OpenSSL](https://blog.kernelcare.com/vulnerability/two-more-vulnerabilities-uncovered-in-openssl)

 Mar 26, 2021, 2:58:12 PM

![Two more vulnerabilities uncovered in OpenSSL](https://blog.kernelcare.com/hs-fs/hubfs/openssl%20cves%20for%20blog.jpeg?width=2600&name=openssl%20cves%20for%20blog.jpeg)

 

OpenSSL, the widely used cryptography toolkit and library, has been the target of security researchers’ audits more than almost any other project, perhaps only excluding the Linux Kernel itself. This week was no exception, and again some issues were found.

 

\[Update 20 April: Over the past weeks, KernelCare has released patches for CVE-2021-3449 covering AlmaLinux OS 8, RHEL 8, Ubuntu 18.04, Ubuntu 20.04, Centos 8, Debian 10, Oracle Linux 8, and for CVE-2021-3450 covering AlmaLinux OS 8, Centos 8, Oracle Linux 8, RHEL 8. If you're running KernelCare on one of those systems, you have already received the patches.\]

[Read More](https://blog.kernelcare.com/vulnerability/two-more-vulnerabilities-uncovered-in-openssl)

[![](https://blog.kernelcare.com/hubfs/openssl%20cves%20for%20blog.jpeg)](https://blog.kernelcare.com/vulnerability/two-more-vulnerabilities-uncovered-in-openssl)

## [Spectre just won't remain dead](https://blog.kernelcare.com/vulnerabilities/spectre-just-wont-remain-dead)

 Mar 19, 2021, 2:49:25 PM

![ Spectre just won't remain dead](https://blog.kernelcare.com/hs-fs/hubfs/222spectre.jpg?width=2600&name=222spectre.jpg)

Shortly after exploit code was [found in a public repository](https://blog.kernelcare.com/vulnerability/thought-spectre-is-history-its-still-alive-and-kicking), two new vulnerabilities ([CVE-2020-27170](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27170) and [CVE-2020-27171](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27171)) have been found in the Linux Kernel code that protects against it.

 

Both vulnerabilities allow a local user to read kernel memory which could contain sensitive information like encryption keys. Proof-of-concept code has also been made available privately, but it is safe to assume it will eventually reach public outlets.

[Read More](https://blog.kernelcare.com/vulnerabilities/spectre-just-wont-remain-dead)

[![](https://blog.kernelcare.com/hubfs/222spectre.jpg)](https://blog.kernelcare.com/vulnerabilities/spectre-just-wont-remain-dead)

## [Three more zombie kernel bugs prove why you must patch consistently](https://blog.kernelcare.com/vulnerabilities/three-more-zombie-kernel-bugs-prove-why-you-must-patch-consistently)

 Mar 16, 2021, 12:36:06 PM

![Three more Zombie kernel bugs prove why you must patch consistently](https://blog.kernelcare.com/hs-fs/hubfs/Zombie%20kernel1.jpeg?width=2600&name=Zombie%20kernel1.jpeg)

Very recently, a long-known vulnerability called Spectre re-emerged due to an exploit that was made available publicly, and a lack of patching meant that this well known vulnerability poses a danger again.

And, yet again, something similar happened. This time, security researchers found three critical bugs in 15-year-old Linux kernel code. Code this old should have been thoroughly scrutinized for bugs by now – and it is anybody’s guess how often these vulnerabilities have been exploited by malicious actors in the meantime.

Patches have now been released for CentOS 8, Oracle EL8, RHEL8, CloudLinux 7h, CloudLinux 8, AlmaLinux OS, Ubuntu Bionic HWE, Debian 10, Debian 10 Cloud, Debian 9 Backports and Proxmox VE6.

Additionally, patches are now also available for CloudLinux 6h, CloudLinux 7, CentOS 7, CentOS 7-plus, Oracle EL7, and RHEL 7.

In this article, we outline the three vulnerabilities just discovered, explain why open-source code is not always scrutinized as well as it should be (or by the right people), and point to the importance of patching consistently.

[Read More](https://blog.kernelcare.com/vulnerabilities/three-more-zombie-kernel-bugs-prove-why-you-must-patch-consistently)

[![](https://blog.kernelcare.com/hubfs/Zombie%20kernel1.jpeg)](https://blog.kernelcare.com/vulnerabilities/three-more-zombie-kernel-bugs-prove-why-you-must-patch-consistently)

## [Mmap kernel vulnerability is relisted](https://blog.kernelcare.com/vulnerability/mmap-kernel-vulnerability-is-relisted)

 Mar 9, 2021, 3:00:00 PM

![Mmap kernel vulnerability is relisted - and what that means for vulnerability management](https://blog.kernelcare.com/hs-fs/hubfs/Cover-1shrink-4.jpg?width=2600&name=Cover-1shrink-4.jpg)

We’ve covered brand new Linux kernel vulnerabilities in a few of our past articles, but in this article we’ll take a look at a vulnerability that’s been *re-listed* accidentally. Both reports – the erroneous relisting, and the original listing – point to a vulnerability in Linux kernel memory mapping where a race condition can develop when a memory expansion function is used.

We’ll cover the vulnerability as it stands. But we’ll also look at a key issue revealed by the double listing: if security experts can so easily lose sight of an existing vulnerability to the extent that a vulnerability is relisted as “new” and “just discovered” – what does it say about the state of vulnerability management?

And what does it mean for Linux users around the globe, vulnerable to countless offensive strategies – but dependent on the security experts for assistance?

 

[Read More](https://blog.kernelcare.com/vulnerability/mmap-kernel-vulnerability-is-relisted)

[![](https://blog.kernelcare.com/hubfs/Cover-1shrink-4.jpg)](https://blog.kernelcare.com/vulnerability/mmap-kernel-vulnerability-is-relisted)

## [Extended Lifecycle Support service providing updated OpenSSL to address CVE-2021-23841](https://blog.kernelcare.com/vulnerability/els-providing-updated-openssl-to-address-cve-2021-23841)

 Mar 4, 2021, 7:00:00 PM

![ELS providing updated OpenSSL to address CVE-2021-23841](https://blog.kernelcare.com/hs-fs/hubfs/OpenSSL%20CVE.jpg?width=2600&name=OpenSSL%20CVE.jpg)

A flaw in the way OpenSSL API function X509\_issuer\_and\_serial\_hash() has been disclosed that may lead applications using it to crash, causing a potential denial-of-service (DoS) to their users. 

 

The flaw lies in the way a hash is calculated from the Issuer and Serial Number data of an X509 certificate, which can make OpenSSL fail returning a NULL value. In turn, this can crash the application calling the function.

[Read More](https://blog.kernelcare.com/vulnerability/els-providing-updated-openssl-to-address-cve-2021-23841)

[![](https://blog.kernelcare.com/hubfs/OpenSSL%20CVE.jpg)](https://blog.kernelcare.com/vulnerability/els-providing-updated-openssl-to-address-cve-2021-23841)

## [QEMU-KVM vhost/vhost\_net Guest to Host Kernel Escape Vulnerability](https://blog.kernelcare.com/qemu-kvm-vhost-vhost-net-guest-to-host-kernel-escape-vulnerability)

 Sep 17, 2019, 7:57:42 PM

![QEMU](https://blog.kernelcare.com/hubfs/QEMU.png)

The KernelCare team are following developments for a recently-reported vulnerability involving QEMU-KVM guests running Linux kernels.

[Read More](https://blog.kernelcare.com/qemu-kvm-vhost-vhost-net-guest-to-host-kernel-escape-vulnerability)

[![](https://blog.kernelcare.com/hubfs/QEMU.png)](https://blog.kernelcare.com/qemu-kvm-vhost-vhost-net-guest-to-host-kernel-escape-vulnerability)

## [SWAPGS: KernelCare patches are on the way](https://blog.kernelcare.com/swapgs-kernelcare-patches-on-the-way-t)

 Aug 7, 2019, 2:30:37 PM

*![swapgs-social](https://blog.kernelcare.com/hs-fs/hubfs/swapgs-social.png?width=1200&name=swapgs-social.png)*

KernelCare patches will start rolling out on Monday, 12 August.

[Read More](https://blog.kernelcare.com/swapgs-kernelcare-patches-on-the-way-t)

[![](https://blog.kernelcare.com/hubfs/swapgs-social.png)](https://blog.kernelcare.com/swapgs-kernelcare-patches-on-the-way-t)

## [SWAPGS: KernelCare patches on the way](https://blog.kernelcare.com/swapgs-kernelcare-patches-on-the-way)

 Aug 7, 2019, 12:22:40 PM

*![swapgs](https://blog.kernelcare.com/hs-fs/hubfs/swapgs.png?width=1200&name=swapgs.png)*

*A new month has started—Summer is in full swing—Must be time for another CPU vulnerability. (Let’s hope this one has a catchy name.)*

[Read More](https://blog.kernelcare.com/swapgs-kernelcare-patches-on-the-way)

[![](https://blog.kernelcare.com/hubfs/swapgs.png)](https://blog.kernelcare.com/swapgs-kernelcare-patches-on-the-way)

 Editor's Picks

## [The Ultimate Guide to Updating Linux Kernel](https://blog.kernelcare.com/the-ultimate-guide-to-updating-linux-kernel)

[KernelCare Team](https://blog.kernelcare.com/author/kernelcare-team) Sep 3, 2020, 1:30:00 PM

## [How to Upgrade An Unsupported OS: An In-depth Checklist](https://blog.kernelcare.com/tutorial/how-to-upgrade-an-unsupported-os-an-in-depth-checklist)

[Joao Correia](https://blog.kernelcare.com/author/correia) Mar 25, 2021, 1:00:00 PM

## [Open-Source Security: What is the Enterprise Impact?](https://blog.kernelcare.com/foss/open-source-security-where-do-enterprise-users-stand)

[Joao Correia](https://blog.kernelcare.com/author/correia) Jan 11, 2021, 4:30:00 PM

## Comments

 Newsletter

 Stay in the Loop

 Subscribe to our newsletter to get the latest news on live patching technology from KernelCare Team.

X

[![](https://blog.kernelcare.com/hubfs/360x280_Popup_Kernel_Blog-1.png)](https://blog.tuxcare.com/)

### [Product](https://www.kernelcare.com/product/)

- [KernelCare+](https://tuxcare.com/live-patching-services/librarycare/)
- [KernelCare Enterprise](https://tuxcare.com/live-patching-services/kernelcare-enterprise/)
- [KernelCare Base](https://tuxcare.com/live-patching-services/)
- [KernelCare for IoT](https://tuxcare.com/live-patching-services/kernelcare-iot/)
- [Pricing](https://www.kernelcare.com/pricing/)
- [Supported Distributions](https://www.kernelcare.com/supported-distributions-and-kernels/)
- [Compare KernelCare with other live patching tools](https://tuxcare.com/compare-live-patching-tools/)

### [Support](https://www.kernelcare.com/support/)

- [Customer Support](https://cloudlinux.zendesk.com/hc/en-us/requests/new)
- [Contact Sales](https://www.kernelcare.com/contact/)
- [Login to CLN](https://cln.cloudlinux.com/console/auth/login?originUrl=%2Fdashboard%2Fproducts)
- [Documentation](https://docs.kernelcare.com/)
- [How to install KernelCare](https://www.kernelcare.com/how-to-install-kernelcare/)
- [Forum](https://cloudlinux.zendesk.com/hc/en-us/community/topics/360001034619-KernelCare-General-Discussion)
- [FAQ](https://www.kernelcare.com/faqs/)
- [Blog](https://blog.kernelcare.com/)
- [Resources](https://www.kernelcare.com/resource/)

### [About](https://www.kernelcare.com/about/)

- [About KernelCare](https://www.kernelcare.com/about/)
- [The Team](https://www.kernelcare.com/about/#the-team)
- [Contact us](https://www.kernelcare.com/contact/)
- [Legal](https://www.kernelcare.com/legal-agreements-for-kernelcare/)

![KernelCare](https://www.kernelcare.com/wp-content/uploads/2019/09/kernelcare-black-and-blue.png)

- [![twitter](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-13.png)](https://twitter.com/kernelcare?lang=en)
- [![facebook](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-14.png)](https://www.facebook.com/kernelcare/)
- [![youtube](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-15.png)](https://www.youtube.com/channel/UCL53jWmZvB6JEd3atIac_SA)
- [![linkedin](https://www.kernelcare.com/wp-content/uploads/2019/09/shape-16.png)](https://www.linkedin.com/showcase/19013359/)

[![privacy shield certified](https://blog.kernelcare.com/hubfs/privacy-shield-certified-logo-2.png "privacy shield certified")](https://blog.kernelcare.com/kernelcare-we-re-soc2-type-i-compliant)

![fips validated](https://blog.kernelcare.com/hubfs/fips-logo.png "privacy shield certified")

![aicpa soc](https://blog.kernelcare.com/hubfs/aicpa-soc-logo-2.png "aicpa soc")

[![pci dss](https://blog.kernelcare.com/hubfs/pci-dss%20(1).png "pci dss")](https://cloudlinux.com/about-us/company/press/1153-cloudlinux-accepted-into-forbes-technology-council)

[![eu gdpr compliant](https://blog.kernelcare.com/hubfs/eu-gdpr-compliant-logo.png "privacy shield certified")](https://blog.kernelcare.com/kernelcare-we-re-soc2-type-i-compliant)

[![eu gdpr compliant](https://blog.kernelcare.com/hubfs/250x250-d-3x.png "forbes")](https://cloudlinux.com/about-us/company/press/1153-cloudlinux-accepted-into-forbes-technology-council)

[![kernelcare](https://www.kernelcare.com/wp-content/uploads/2019/09/kernelcare-white-193x40.png "cl-fr-logo")](https://cloudlinux.com/)

KernelCare is a product of [CloudLinux](https://cloudlinux.com/), the company that is making Linux secure, stable and profitable since 2009.  
 Its flagship product, CloudLinux OS, powers over 20 million websites.

© 2020 ALL RIGHTS RESERVED. [CLOUDLINUX INC.](https://cloudlinux.com/) 

[![ClickCease](https://monitor.clickcease.com/stats/stats.aspx)](https://www.clickcease.com)