Skip to content
License.Markets
Instant Activation

KernelCare License

Security

Applies Linux kernel security patches to a running server, so kernel vulnerabilities can be closed without scheduling a reboot.

License Scope
Per server (IP-based)
Platform
Linux
Reboot Required
No

Pricing

  • Monthly

    $2/mo

Enquire about this license
  • Not currently self-service — we confirm price and availability before you pay
  • Activated automatically after checkout
  • Delivery: Instant activation
  • License Scope: Per server (IP-based)
  • Payment handled by the payment provider

Prices exclude any applicable tax. Licenses are issued to the account used at checkout.

Overview

KernelCare patches the running kernel in place. Without it, a kernel security fix is only in effect after a reboot, which on a shared hosting server means either taking customer sites down or leaving the vulnerability open until a maintenance window arrives — and in practice that window is often weeks away. KernelCare removes that trade-off by loading the patch into the live kernel. It also patches shared userspace libraries such as glibc and OpenSSL, which have the same restart problem at the process level. Licenses are issued per server and validate against the server IP address.

Features

  • Rebootless kernel patching

    Security fixes are applied to the running kernel, so no reboot and no downtime is needed to close a vulnerability.

  • Automatic patch checks

    The agent polls for new patches on a schedule and applies them without an administrator having to act.

  • Userspace library patching

    Patches shared libraries such as glibc and OpenSSL in running processes, which otherwise require a service restart.

  • Rollback

    Applied patches can be removed from the running kernel if a change needs to be reverted.

  • Compliance evidence

    Reports which CVEs are patched on each server, which is what an audit asks for.

Specifications

License Scope
Per server (IP-based)
Platform
Linux
Reboot Required
No
Delivery
Instant activation

System requirements

Operating system

  • AlmaLinux OS 8 or 9
  • Rocky Linux 8 or 9
  • CloudLinux OS 7, 8 or 9
  • CentOS 7
  • Ubuntu 20.04 / 22.04 LTS
  • Debian 10, 11 or 12

Kernel

  • A distribution-supplied kernel — custom-compiled kernels are not patchable

Other

  • Root/SSH access to the server
  • Outbound HTTPS access to the patch server

Installation

The KernelCare agent is installed over SSH as root and registered with the license key issued at checkout. It applies any outstanding patches to the running kernel on its first run, with no reboot required.

Frequently asked questions

Does KernelCare replace kernel updates entirely?

No. It closes security vulnerabilities in the running kernel between reboots. Kernel package updates still install as usual and take effect at the next reboot, whenever that happens.

Does it work on a custom-compiled kernel?

No. Patches are built against the distribution's own kernel builds, so a custom-compiled kernel cannot be patched.

Is KernelCare included with CloudLinux OS?

No. It is licensed separately, though the two are commonly run together on the same server.

Related licenses

CloudLinux OS License

Instant activation

A shared hosting operating system that isolates each account into its own lightweight container to contain resource abuse.

From$4.50/mo

Imunify360 License

Instant activation

A complete security suite for Linux hosting servers combining a web application firewall, malware scanning and automated patching.

Popular

From$2/mo

CPGuard License

Instant activation

A server security suite combining malware scanning, a web application firewall and real-time protection for hosting control panels.

From$2/mo

cPanel & WHM License

Instant activation

The industry-standard Linux hosting control panel, licensed without an account cap and bundled with Softaculous, SitePad and FleetSSL for the same server.

Popular

From$4.50/mo