Описание
ELSA-2026-39323: pacemaker security update (IMPORTANT)
[2.1.10-3.0.1]
- Replace bug url [Orabug: 34202300]
- Upstream reference in pacemaker crm_report binary [Orabug: 32825154]
[2.1.10-3]
- Fix integer overflows in remote message decompression code (CVE-2026-10649)
- Resolves: RHEL-181150
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
pacemaker
2.1.10-3.0.1.el9_8
pacemaker-cli
2.1.10-3.0.1.el9_8
pacemaker-remote
2.1.10-3.0.1.el9_8
pacemaker-cluster-libs
2.1.10-3.0.1.el9_8
pacemaker-libs
2.1.10-3.0.1.el9_8
pacemaker-schemas
2.1.10-3.0.1.el9_8
Oracle Linux x86_64
pacemaker
2.1.10-3.0.1.el9_8
pacemaker-cli
2.1.10-3.0.1.el9_8
pacemaker-remote
2.1.10-3.0.1.el9_8
pacemaker-cluster-libs
2.1.10-3.0.1.el9_8
pacemaker-libs
2.1.10-3.0.1.el9_8
pacemaker-schemas
2.1.10-3.0.1.el9_8
Связанные CVE
Связанные уязвимости
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
A flaw was found in Pacemaker. An unauthenticated remote attacker can ...