Security advisories affecting cPanel, CloudLinux, LiteSpeed and CSF — including a root-access fix for ConfigServer Firewall. Check if your server is affected

LicenseW logo

TuxCare ELS + KernelCare Now Included With Your CloudLinux License

Updated August 10, 20264 views

Two security products have been added to your CloudLinux license, for $0.49 a month. Here is exactly what that buys you — and why we think it is the best $0.49 on your invoice.


The short version

What's newKernelCare and TuxCare Endless Lifecycle Support, both included
What it costs$3.50 → $3.99/month — just $0.49 more
What you doTwo commands, no reboot, no downtime
What it protectsYour kernel, and every end-of-life PHP, Python, Node.js and Ruby version on the server

If you only read this far: your server can now be fully patched without a single reboot, and your old PHP sites stop being a liability. Skip to how to turn it on.


Why we did this

Two things kept coming up in support tickets.

"I can't upgrade PHP — the site will break." We hear this constantly, and it is almost always true. The application was built for PHP 7.4, the developer has moved on, and upgrading means a rewrite nobody budgeted for. So the site stays on an end-of-life version that has not had a security patch since 2022.

"I'll reboot for the kernel patch at the weekend." And then the weekend comes and there is always a reason not to. Meanwhile a public root exploit sits unpatched on a server full of customer sites.

Both problems have the same shape: the fix exists, but taking it costs you something you cannot afford right now. So it gets deferred, and the risk quietly accumulates.

These two products remove the cost of taking the fix.


KernelCare: patch the kernel, keep the server up

Linux kernel vulnerabilities are found constantly, and the serious ones are local privilege escalation — an ordinary user becomes root. On a shared server, that means one compromised account owns every site on the machine.

The patch always exists. The problem is that applying it means a reboot: a maintenance window, a warning to customers, every site down for the duration, and someone awake to check it comes back.

KernelCare applies kernel security patches to the running kernel. No reboot. No maintenance window. No downtime. The patch is live within minutes of release instead of whenever you next find a convenient Sunday night.

This is what "live kernel patching" and "rebootless kernel updates" mean in practice: your uptime and your security stop being a trade-off.

What it is worth to you

Count your last twelve months. How many kernel reboots did you schedule — and how many did you skip? Every skipped one was a window where a known, published exploit worked on your server.

KernelCare costs you $0.49 a month — about 1.6 cents a day. One prevented incident, or one 2am maintenance window you did not have to sit through, and it has already paid for itself many times over.


TuxCare ELS: keep old PHP safe without upgrading

TuxCare Endless Lifecycle Support — also sold as Extended Lifecycle Support — takes security fixes released for modern versions and backports them into the old ones.

Your PHP 7.4 stays PHP 7.4. Same behaviour, same compatibility, same application, same plugins. It simply keeps receiving security patches, as though it were still supported.

What's covered

LanguageVersions kept patched
PHP5.6, 7.0, 7.1, 7.2, 7.3, 7.4
Python2.7 and other retired branches
Node.jsRetired LTS branches
RubyRetired branches

If you have been putting off a PHP 7.4 end of life migration, or still have a Python 2.7 script running something important, this is the answer that does not involve rewriting it.

What it is worth to you

Price a PHP 7.4 → 8.x migration on a real site: plugin compatibility testing, theme fixes, a staging environment, and the risk of breaking a store that earns money. That is days of developer time — or a bill from whoever you hire to do it.

TuxCare ELS buys you the security of a supported version without the migration. Not forever, and not as an excuse never to upgrade — but on your schedule instead of an attacker's.


The honest maths on $0.49

We are not going to insult you by pretending a price increase is a gift. So here it is plainly.

Your license goes from $3.50 to $3.99 a month. That $0.49 — roughly 1.6 cents a day — adds two products that are normally sold separately, covering the two most common ways a hosting server gets compromised: an unpatched kernel, and unpatched end-of-life language runtimes.

Set that against what you already spend:

  • One hour of a developer's time costs more than this will all year
  • One 15-minute outage across every site on your server costs you more in goodwill alone
  • One security incident — the cleanup, the customer conversations, the reputation — is not comparable at all

And what you were already paying for CloudLinux does not change: CageFS isolation, LVE resource limits, the hardened PHP selector, MySQL Governor, SecureLinks. Those all remain. This is genuinely two additions, not a repackaging.

If you would rather not have them, tell us. We would rather have the conversation than have you feel something was slipped onto your invoice.


Already active on your license

Both were enabled on your license from our side. There is nothing to install and nothing to run — no reinstall, no reboot, no downtime.

Confirming it on your server

Terminal
# ELS repositories enabled?
dnf repolist 2>/dev/null | grep -i tuxcare || yum repolist 2>/dev/null | grep -i tuxcare

# KernelCare active?
kcarectl --info 2>/dev/null | head -5

If either command comes back empty, open a ticket with the output and we will sort it out for you.


Questions people actually ask

Does this mean my old PHP is now as good as PHP 8? No — and we will not pretend otherwise. An end-of-life version still lacks the performance and features of a current release. What you get is security, and therefore time: run legacy software safely while you plan the upgrade properly, rather than being forced into it by a vulnerability disclosure.

Should I still upgrade eventually? Where it is realistic, yes. ELS is protection for the period before you can, not an argument against ever doing it.

Is KernelCare free? It is included with your license at no separate charge — that is what the $0.49 covers, alongside ELS. You never pay KernelCare separately.

Do I need to reinstall CloudLinux? No. Both attach to the license you already have.

Will my sites go down when patches apply? No. KernelCare patches the running kernel in place; ELS patches arrive through your normal package updates.

I run one site on a VPS — do I need this? Less urgently than a shared host, but the same logic holds. If that site runs end-of-life PHP and you cannot easily upgrade it, this is the alternative to leaving it unpatched.

What about CentOS 7? CentOS 7 reached end of life in June 2024. If you are still on it, extended support for the OS itself is a separate conversation — open a ticket and we will talk through your options honestly.

Can I decline the increase? Talk to us. We would rather understand your situation than lose you over $0.49.


Not sure whether any of this applies to your server? Open a ticket with your PHP version and we will tell you straight whether you need it — including if the answer is that you do not.

Still need help?

Our support team is available to assist with license installation and troubleshooting.

Open Support Ticket

Was this article helpful?

Need help? Chat with us