Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:40833

Опубликовано: 22 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: pacemaker security update

The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures.

Security Fix(es):

  • pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
pacemaker-schemasnoarch5.el10_2.1pacemaker-schemas-3.0.1-5.el10_2.1.noarch.rpm
pacemaker-libsx86_645.el10_2.1pacemaker-libs-3.0.1-5.el10_2.1.x86_64.rpm
pacemaker-cluster-libsx86_645.el10_2.1pacemaker-cluster-libs-3.0.1-5.el10_2.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
redhat
около 2 месяцев назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
nvd
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
debian
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can ...

suse-cvrf
около 1 месяца назад

Security update for pacemaker