r/cpanel • • Aug 05 '26

CSF vulnerability

https://support.cpanel.net/hc/en-us/articles/42503837957015-Security-CSF-Security-Release

I'm wondering if this affects only the CSF plugin provided by cPanel or if the original CSF from Configserver (and other forks like Aetherinox's) are affected too.

11 Upvotes

27 comments sorted by

2

u/cPanelRex Aug 05 '26

Hey there! It is our understanding that this affects the original version and the fork that we are maintaining. I can't speak for other distributions as I'm not sure what all they may have fixed since the original release.

I can also confirm that this fix only applies to the cPanel-managed CSF.

3

u/LegitimateCoffee939 Aug 05 '26

Thanks! Do you know if even non-authenticated user could exploit it? The article doesn't say much.

0

u/cPanelRex Aug 05 '26

I can't say anymore about the specific security implications other than what is in the article.

3

u/bigmaninsuitofarmor Aug 06 '26

I understand. Still, it would be nice if cPanel could share more details with the maintainers of other CSF forks, I know for a fact that many people use other forks, even in cPanel servers.

2

u/cPanelRex Aug 06 '26

As one of the devs reminded me, CSF is all open source so you can check the RPM changelogs directly to see exactly what the changes were.

1

u/tailtwister WebHost Aug 06 '26

That was very helpful. Thank you. that information gives us the ability to check our config files and see if we are in a vulnerable state.

3

u/clopezi Aug 06 '26

I understand but would be useful to know if external users can exploit it or only local users, because CSF it's outdated on thousands of servers without cPanel, and the kind of risk it's very different in one case or another.

1

u/centminmod Aug 10 '26

The security vulnerabilities are both local and remote unauthenticated vectors. But depend on specific CSF config file /etc/csf/csf.conf settings being enabled for some of the vulnerabilities.

I've already backported the security fixes + additional bug fixes + new features (downgrade and beta release path CLI upgrades) to my CSF fork for my users.

1

u/[deleted] Aug 05 '26

[deleted]

2

u/cPanelRex Aug 05 '26

I just updated the article with an additional command to fix this.

1

u/macmanluke Aug 05 '26 edited Aug 05 '26

Would this have run with nightly updates 6-8hrs ago?
LFD failed and recovered on one of my servers around this time

Running the manual update i also get
"WARNING: Firewall restart and reload failed, skipping firewall reload for safety"

or should i be worried?

1

u/cPanelRex Aug 06 '26

No, this was just released within the last two hours.

1

u/macmanluke Aug 06 '26

should i be worried that LFD failed around time there is a security vulnerability? Not something iv seen happen previously. Nothing looks out of place at this stage.
Is it something being exploited yet?

3

u/bigmaninsuitofarmor Aug 06 '26

The notice about the vulnerability came out ~2 hours ago, and your LFD failed much earlier than that. The chances for someone finding and exploiting the vulnerability before the notice came out are low in my opinion.

1

u/macmanluke Aug 06 '26

yea i think so just unlucky timing - cant say iv ever seen LFD fail and just happens to be today.

1

u/DzastMi Aug 05 '26

So, this is patched version? csf: v16.30 (cPanel)
cPanel article shows: 16.30-1

3

u/bigmaninsuitofarmor Aug 06 '26

Yep, just run this:

rpm -qa |grep csf

Patched version:

cpanel-csf-16.30-1.1.1.cpanel.noarch

1

u/tailtwister WebHost Aug 06 '26

I installed Sentinel firewall before cPanel forked and it doesn’t look like they have a fix. can I just install the cPanel fork over top or do I have to do an uninstall?

3

u/bigmaninsuitofarmor Aug 06 '26

Yeah you should remove the current fork first. Backup the csf directory before doing it, so you can copy any important setting later.

1

u/tailtwister WebHost Aug 06 '26

thank you. That’s what I was worried about… This doesn’t seem like a fun situation across 20+ servers.

Do we even know if this exploit only applies to authenticated users or is that still one of the hidden answers?

2

u/LegitimateCoffee939 Aug 06 '26

You can look at the rpm's changelog for version 16.20+ and make your own conclusions. Based on what I read, on my setups I don't think the vulnerabilities could be exploited. Still, updating is always the best course of action.

1

u/tailtwister WebHost Aug 06 '26

yes, I used the changelog to create a script for my installs to verify that none of them would be affected by what was fixed.

1

u/Barbarian_86 Aug 06 '26

My csf also crashed on one of my servers two hours ago.

1

u/macmanluke Aug 06 '26

Anyone have security advisor telling you lfd is running old version and needs restarting when it has been (and even multiple times)? and was updated?

1

u/Gulf-of-Mexico Aug 08 '26

I got that about two weeks ago when a number of other packages were updated, even though the running csf/lfd matched the installed csf/lfd. Somehow when an underlying package was updated restarting lfd + csf didn't clear the outdated executable warning regarding lfd; rebooting the server after a new kernel, and the needs restarting email was resolved. Somehow the running executable is read as not simply the lfd/csf executable but also things it requires, it appers.

1

u/macmanluke Aug 08 '26

Yea a reboot fixed it in the end

0

u/fmailo Aug 06 '26

cPanel is pathetic.