Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-39323

Опубликовано: 21 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-39323: pacemaker security update (IMPORTANT)

[2.1.10-3.0.1]

  • Replace bug url [Orabug: 34202300]
  • Upstream reference in pacemaker crm_report binary [Orabug: 32825154]

[2.1.10-3]

  • Fix integer overflows in remote message decompression code (CVE-2026-10649)
  • Resolves: RHEL-181150

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

pacemaker

2.1.10-3.0.1.el9_8

pacemaker-cli

2.1.10-3.0.1.el9_8

pacemaker-remote

2.1.10-3.0.1.el9_8

pacemaker-cluster-libs

2.1.10-3.0.1.el9_8

pacemaker-libs

2.1.10-3.0.1.el9_8

pacemaker-schemas

2.1.10-3.0.1.el9_8

Oracle Linux x86_64

pacemaker

2.1.10-3.0.1.el9_8

pacemaker-cli

2.1.10-3.0.1.el9_8

pacemaker-remote

2.1.10-3.0.1.el9_8

pacemaker-cluster-libs

2.1.10-3.0.1.el9_8

pacemaker-libs

2.1.10-3.0.1.el9_8

pacemaker-schemas

2.1.10-3.0.1.el9_8

Связанные CVE

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
redhat
около 2 месяцев назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
nvd
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
debian
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can ...

suse-cvrf
около 1 месяца назад

Security update for pacemaker