AlmaLinux 2266 Published by

A pcs security and bug fix update has been released for AlmaLinux 8.



ALSA-2023:3082 Moderate: pcs security and bug fix update


Type:
security

Severity:
moderate

Release date:
2023-05-19

Description
Security Fix(es):
* rubygem-rack: Denial of service in Multipart MIME parsing (CVE-2023-27530)
* rubygem-rack: denial of service in header parsing (CVE-2023-27539)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Command 'pcs config checkpoint diff' does not show configuration differences between checkpoints (BZ#2180700)
* Need a way to add a scsi fencing device to a cluster without requiring a restart of all cluster resources (BZ#2180706)

References:
RHSA-2023:3082
CVE-2023-27530
CVE-2023-27539
ALSA-2023:3082

Updates packages:
pcs-snmp-0.10.15-4.el8_8.1.alma.x86_64.rpm
pcs-0.10.15-4.el8_8.1.alma.x86_64.rpm
pcs-snmp-0.10.15-4.el8_8.1.alma.aarch64.rpm
pcs-0.10.15-4.el8_8.1.alma.aarch64.rpm
pcs-0.10.15-4.el8_8.1.alma.ppc64le.rpm
pcs-snmp-0.10.15-4.el8_8.1.alma.ppc64le.rpm
pcs-0.10.15-4.el8_8.1.alma.s390x.rpm
pcs-snmp-0.10.15-4.el8_8.1.alma.s390x.rpm

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

  ALSA-2023:3082 Moderate: pcs security and bug fix update