Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:48585

Опубликовано: 31 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: fence-agents security update

The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.

Security Fix(es):

  • httplib2: httplib2: Denial of Service via unbounded decompression of HTTP response bodies (CVE-2026-59939)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
fence-agents-wtinoarch21.el10_2.5fence-agents-wti-4.16.0-21.el10_2.5.noarch.rpm
fence-agents-amt-wsnoarch21.el10_2.5fence-agents-amt-ws-4.16.0-21.el10_2.5.noarch.rpm
fence-agents-rhevmnoarch21.el10_2.5fence-agents-rhevm-4.16.0-21.el10_2.5.noarch.rpm
fence-agents-intelmodularnoarch21.el10_2.5fence-agents-intelmodular-4.16.0-21.el10_2.5.noarch.rpm
fence-agents-commonaarch6421.el10_2.5fence-agents-common-4.16.0-21.el10_2.5.aarch64.rpm
fence-agents-kdumpaarch6421.el10_2.5fence-agents-kdump-4.16.0-21.el10_2.5.aarch64.rpm
fence-agents-ipdunoarch21.el10_2.5fence-agents-ipdu-4.16.0-21.el10_2.5.noarch.rpm
fence-agents-apc-snmpnoarch21.el10_2.5fence-agents-apc-snmp-4.16.0-21.el10_2.5.noarch.rpm
fence-agents-vmware-restnoarch21.el10_2.5fence-agents-vmware-rest-4.16.0-21.el10_2.5.noarch.rpm
fence-agents-cisco-ucsnoarch21.el10_2.5fence-agents-cisco-ucs-4.16.0-21.el10_2.5.noarch.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

CVSS3: 7.5
redhat
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

CVSS3: 7.5
nvd
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

CVSS3: 7.5
debian
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0 ...

rocky
4 дня назад

Important: fence-agents security update