Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:1239

Опубликовано: 11 фев. 2026
Источник: rocky
Оценка: Important

Описание

Important: fence-agents security update

The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.

Security Fix(es):

  • urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion (CVE-2025-66418)

  • urllib3: urllib3 Streaming API improperly handles highly compressed data (CVE-2025-66471)

  • urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) (CVE-2026-21441)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
fence-agents-aliyunx86_6498.el9_7.4fence-agents-aliyun-4.10.0-98.el9_7.4.x86_64.rpm
fence-agents-allx86_6498.el9_7.4fence-agents-all-4.10.0-98.el9_7.4.x86_64.rpm
fence-agents-amt-wsnoarch98.el9_7.4fence-agents-amt-ws-4.10.0-98.el9_7.4.noarch.rpm
fence-agents-apcnoarch98.el9_7.4fence-agents-apc-4.10.0-98.el9_7.4.noarch.rpm
fence-agents-apc-snmpnoarch98.el9_7.4fence-agents-apc-snmp-4.10.0-98.el9_7.4.noarch.rpm
fence-agents-awsx86_6498.el9_7.4fence-agents-aws-4.10.0-98.el9_7.4.x86_64.rpm
fence-agents-azure-armx86_6498.el9_7.4fence-agents-azure-arm-4.10.0-98.el9_7.4.x86_64.rpm
fence-agents-bladecenternoarch98.el9_7.4fence-agents-bladecenter-4.10.0-98.el9_7.4.noarch.rpm
fence-agents-brocadenoarch98.el9_7.4fence-agents-brocade-4.10.0-98.el9_7.4.noarch.rpm
fence-agents-cisco-mdsnoarch98.el9_7.4fence-agents-cisco-mds-4.10.0-98.el9_7.4.noarch.rpm

Показывать по

Связанные уязвимости

suse-cvrf
30 дней назад

Security update for python-urllib3_1

suse-cvrf
около 1 месяца назад

Security update for python-urllib3_1

suse-cvrf
около 1 месяца назад

Security update for python-urllib3

rocky
около 1 месяца назад

Important: python-urllib3 security update

rocky
около 1 месяца назад

Important: fence-agents security update