Описание
ELSA-2026-39322: pacemaker security update (IMPORTANT)
[2.1.7-5.6.0.1]
- Upstream reference in pacemaker crm_report binary [Orabug: 32825154]
- Replace bug url [Orabug: 34202300]
[2.1.7-5.6]
- Fix integer overflows in remote message decompression code (CVE-2026-10649)
- Resolves: RHEL-181157
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
pacemaker
2.1.7-5.6.0.1.el8_10
pacemaker-cli
2.1.7-5.6.0.1.el8_10
pacemaker-cluster-libs
2.1.7-5.6.0.1.el8_10
pacemaker-libs
2.1.7-5.6.0.1.el8_10
pacemaker-remote
2.1.7-5.6.0.1.el8_10
pacemaker-schemas
2.1.7-5.6.0.1.el8_10
Oracle Linux x86_64
pacemaker
2.1.7-5.6.0.1.el8_10
pacemaker-cli
2.1.7-5.6.0.1.el8_10
pacemaker-cluster-libs
2.1.7-5.6.0.1.el8_10
pacemaker-libs
2.1.7-5.6.0.1.el8_10
pacemaker-remote
2.1.7-5.6.0.1.el8_10
pacemaker-schemas
2.1.7-5.6.0.1.el8_10
Связанные CVE
Связанные уязвимости
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
A flaw was found in Pacemaker. An unauthenticated remote attacker can ...