AlmaLinux 2266 Published by

A pcs security and bug fix update has been released for AlmaLinux 9.



ALSA-2023:2652 Important: pcs security and bug fix update


Type:
security

Severity:
important

Release date:
2023-05-11

Description
Security Fix(es):
* pcs: webpack: Regression of CVE-2023-28154 fixes in the AlmaLinux (CVE-2023-2319)
* rubygem-rack: Denial of service in Multipart MIME parsing (CVE-2023-27530)
* rubygem-rack: denial of service in header parsing (CVE-2023-27539)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Command 'pcs config checkpoint diff' does not show configuration differences between checkpoints (BZ#2180697)
* Need a way to add a scsi fencing device to a cluster without requiring a restart of all cluster resources (BZ#2180704)
* WebUI fence levels prevent loading of cluster status (BZ#2183180)

References:
RHSA-2023:2652
CVE-2023-2319
CVE-2023-27530
CVE-2023-27539
ALSA-2023:2652

Updates packages:
pcs-snmp-0.11.4-7.el9_2.x86_64.rpm
pcs-0.11.4-7.el9_2.x86_64.rpm
pcs-0.11.4-7.el9_2.s390x.rpm
pcs-snmp-0.11.4-7.el9_2.s390x.rpm
pcs-snmp-0.11.4-7.el9_2.ppc64le.rpm
pcs-0.11.4-7.el9_2.ppc64le.rpm
pcs-snmp-0.11.4-7.el9_2.aarch64.rpm
pcs-0.11.4-7.el9_2.aarch64.rpm

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

  ALSA-2023:2652 Important: pcs security and bug fix update