A couple weeks ago Redhat released a set of patches which now seem to fix the issue, we are also getting confirmed reports that the fix from Redhat does resolve this. The ultimate cause and fix can be identified in their article here. Regarding the updates and changes to microcode_ctl – the correct version yum should request for you to install will be microcode_ctl-2.1-61.10.el7_8.x86_64.rpm. If you are given output above that does not match the version, please open a ticket to our support team to review.
We have observed an issue with a specific CVE update that affects the following system profile:
- Self-Managed SuperMicro Server (our managed customers need not take any action)
- Motherboard: X11SSL-F
- Processor: E3-12XX v5 Skylake
- Red Hat Enterprise Linux 7, CentOS 7 or CloudLinux 7 Installed
In relation to the recent CVE-2020-0543 that was released and patched on June 10th, 2020, at approximately 9 PM Eastern, we received multiple reports of servers having crashed at the UPCP script for cPanel. At this time, it appears that only the aforementioned hardware configuration with this software is affected, although we are still investigating. We recommend you do not perform any kernel updates at this time. You can disable automatic updates via command line (previous instruction via WHM no longer exists in latest versions of cPanel) by following the instruction below. Feel free to open a support ticket if you would like our assistance with this.
As of version 88, cPanel no longer allows you to disable automatic updates via WHM. This must be done via CLI.
In order to disable automatic updates on your cPanel server:
- SSH to your server or utilize WHM’s “Terminal” application if it is enabled
- Using your favorite text editor (vi, nano) edit /etc/cpupdate.conf
- Change the “daily” setting to “manual” for the RPMUP and UPDATES options
Below is an example of a /etc/cpupdate.conf file with updates disabled:
To confirm that updates are disabled:
- Log into WHM
- Go to ‘Server Configuration’ -> ‘Update Preferences’
- Confirm that the message ‘Warning Automatic updates are disabled for this server. We strongly recommend enabling automatic updates’ displays at the top of the page.
- CVE Info: https://access.redhat.com/security/cve/CVE-2020-0543
- Redhat Security Advisory: https://access.redhat.com/errata/RHSA-2020:2432