Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:39323

Опубликовано: 15 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: pacemaker security update

The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures.

Security Fix(es):

  • pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
pacemaker-cluster-libsi6863.el9_8pacemaker-cluster-libs-2.1.10-3.el9_8.i686.rpm
pacemaker-cluster-libsx86_643.el9_8pacemaker-cluster-libs-2.1.10-3.el9_8.x86_64.rpm
pacemaker-libsi6863.el9_8pacemaker-libs-2.1.10-3.el9_8.i686.rpm
pacemaker-libsx86_643.el9_8pacemaker-libs-2.1.10-3.el9_8.x86_64.rpm
pacemaker-schemasnoarch3.el9_8pacemaker-schemas-2.1.10-3.el9_8.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
redhat
около 2 месяцев назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
nvd
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
debian
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can ...

suse-cvrf
около 1 месяца назад

Security update for pacemaker