Help Center/ Cloud Container Engine/ FAQs/ Node/ OSs/ Why Performance May Deteriorate When Nodes of Specific Flavors Use Ubuntu 22.04 Images?
Updated on 2026-09-29 GMT+08:00

Why Performance May Deteriorate When Nodes of Specific Flavors Use Ubuntu 22.04 Images?

Description

When nodes of certain flavors use Ubuntu 22.04, overall system performance or the performance of specific applications may deteriorate.

The following instance flavors are affected:

  • General computing-plus: aC series
  • Memory-optimized: aM series

Possible Cause

This performance change is caused by the SafeRET security mitigation introduced by the Linux kernel community to address a CPU vulnerability known as Speculative Return Stack Overflow (SRSO) (CVE-2023-20569).

The SafeRET mechanism prevents attacks by adding extra security checks and instruction sequences. These operations introduce additional CPU overhead under specific workloads, which may reduce processor performance. In general production environments, the overall security risk related to SRSO is considered relatively low.

Solution

You can choose whether to disable the SafeRET mitigation based on your service scenario's security and performance priorities. For details, see What Should I Do If the Performance of a Linux ECS Deteriorates After the Kernel Is Updated?