Nyheter & Meddelanden
- fredag, 1st Maj, 2026
- 09:54jag
We are issuing an important notice regarding a kernel-level vulnerability affecting CloudLinux systems.
Official advisory:
https://blog.cloudlinux.com/cve-2026-31431-copy-fail-mitigation-and-patches
Vulnerability ID: CVE-2026-31431
Severity: High
Component: Linux Kernel (copy_file_range system call)
What is the issue?
This issue is related to the Linux kernel’s copy_file_range function, which is used internally for efficient file copying.
Due to a flaw in the kernel implementation, file copy operations may behave incorrectly, leading to:
- Silent data corruption
- Incomplete file copies
- Unexpected failures during file operations
This issue is particularly critical because it may not generate visible errors, making it difficult to detect.
What is the risk?
- Corrupted backups without warning
- Broken website files or application data
- Data inconsistency during migrations
- Integrity issues in storage and backup systems
This directly impacts hosting environments using backup systems such as JetBackup, rsync, or any tool relying on kernel-level file copying.
Who is affected?
- CloudLinux servers running affected kernel versions
- Systems performing frequent file operations (backups, restores, migrations)
- cPanel/WHM servers using CloudLinux
Actions taken by HostRainbow
- Reviewed all CloudLinux-based servers
- Applied patched kernel updates where available
- Verified backup integrity and file consistency
- Enabled additional monitoring for file operations
All managed HostRainbow servers are being secured and monitored.
Required actions for unmanaged or self-managed servers
If you are managing your own server, follow these steps immediately:
1. Update CloudLinux packages and kernel
dnf update -y
2. Reboot the server (Required)
Apply the updated kernel:
reboot
3. Verify kernel version
uname -r
Ensure the kernel version matches the patched release provided by CloudLinux.
4. Apply CloudLinux mitigation (if update not yet applied)
CloudLinux recommends disabling the use of copy_file_range in affected environments until fully patched.
5. Verify backups and data integrity
- Check recent backups for corruption
- Test restore points
- Re-run backups where necessary
6. Monitor file operations
- Validate file sizes after copy
- Use checksums (md5/sha256) to verify integrity
- Watch for unusual behavior in backup or migration tools
Important note
If your server was running an affected kernel, there is a risk that file operations performed during that period may be unreliable.
Recommended:
- Re-verify critical website and database files
- Re-run recent backups
- Audit important data for consistency
Need assistance?
If you need help updating your server, verifying data integrity, or applying mitigation steps, our support team is available to assist.
Team HostRainbow
Hostrainbow is a web hosting provider offering shared hosting, VPS, dedicated servers, and domain registration. Known for reliability, security, and user-friendly services, they cater to both individuals and businesses seeking robust online solutions.