Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-39322

Опубликовано: 15 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-39322: pacemaker security update (IMPORTANT)

[2.1.7-5.6.0.1]

  • Upstream reference in pacemaker crm_report binary [Orabug: 32825154]
  • Replace bug url [Orabug: 34202300]

[2.1.7-5.6]

  • Fix integer overflows in remote message decompression code (CVE-2026-10649)
  • Resolves: RHEL-181157

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

pacemaker

2.1.7-5.6.0.1.el8_10

pacemaker-cli

2.1.7-5.6.0.1.el8_10

pacemaker-cluster-libs

2.1.7-5.6.0.1.el8_10

pacemaker-libs

2.1.7-5.6.0.1.el8_10

pacemaker-remote

2.1.7-5.6.0.1.el8_10

pacemaker-schemas

2.1.7-5.6.0.1.el8_10

Oracle Linux x86_64

pacemaker

2.1.7-5.6.0.1.el8_10

pacemaker-cli

2.1.7-5.6.0.1.el8_10

pacemaker-cluster-libs

2.1.7-5.6.0.1.el8_10

pacemaker-libs

2.1.7-5.6.0.1.el8_10

pacemaker-remote

2.1.7-5.6.0.1.el8_10

pacemaker-schemas

2.1.7-5.6.0.1.el8_10

Связанные CVE

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
redhat
около 2 месяцев назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
nvd
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
debian
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can ...

suse-cvrf
около 1 месяца назад

Security update for pacemaker