Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:47736

Опубликовано: 30 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: fence-agents security update

The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.

Security Fix(es):

  • httplib2: httplib2: Denial of Service via unbounded decompression of HTTP response bodies (CVE-2026-59939)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
fence-agents-cisco-mdsnoarch129.el8_10.27fence-agents-cisco-mds-4.2.1-129.el8_10.27.noarch.rpm
fence-agents-cisco-ucsnoarch129.el8_10.27fence-agents-cisco-ucs-4.2.1-129.el8_10.27.noarch.rpm
fence-agents-allaarch64129.el8_10.27fence-agents-all-4.2.1-129.el8_10.27.aarch64.rpm
fence-agents-amt-wsnoarch129.el8_10.27fence-agents-amt-ws-4.2.1-129.el8_10.27.noarch.rpm
fence-agents-apcnoarch129.el8_10.27fence-agents-apc-4.2.1-129.el8_10.27.noarch.rpm
fence-agents-apc-snmpnoarch129.el8_10.27fence-agents-apc-snmp-4.2.1-129.el8_10.27.noarch.rpm
fence-agents-bladecenternoarch129.el8_10.27fence-agents-bladecenter-4.2.1-129.el8_10.27.noarch.rpm
fence-agents-brocadenoarch129.el8_10.27fence-agents-brocade-4.2.1-129.el8_10.27.noarch.rpm
fence-agents-commonnoarch129.el8_10.27fence-agents-common-4.2.1-129.el8_10.27.noarch.rpm
fence-agents-computenoarch129.el8_10.27fence-agents-compute-4.2.1-129.el8_10.27.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

CVSS3: 7.5
redhat
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

CVSS3: 7.5
nvd
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

CVSS3: 7.5
debian
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0 ...

rocky
3 дня назад

Important: fence-agents security update