Security News

Cybersecurity news aggregator

🐧
HIGH Updates Red Hat Errata

RHSA-2026:11495: Important: pcs security update

This security update addresses two high-severity vulnerabilities in the `pcs` cluster configuration tool: a Denial of Service (DoS) via large multipart bodies in Tornado (CVE-2026-31958, CVSS 7.5) and arbitrary code execution via untrusted input in lodash (CVE-2026-4800, CVSS 8.1). The vulnerabilities affect `pcs` packages for Red Hat Enterprise Linux 8.8 specialized update services, specifically where the underlying components use Tornado versions prior to 6.5.5 and lodash versions prior to 4.17.21. The advisory provides updated `pcs` packages that incorporate the fixed versions of these dependencies to remediate the issues.
Read Full Article →

Red Hat Product Errata RHSA-2026:11495 - Security Advisory Issued: 2026-04-29 Updated: 2026-04-29 RHSA-2026:11495 - Security Advisory Overview Updated Packages Synopsis Important: pcs security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for pcs is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. Security Fix(es): tornado-python: Tornado: Denial of Service via large multipart bodies (CVE-2026-31958) lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Red Hat Enterprise Linux High Availability for x86_64 - Telecommunications Update Service 8.8 x86_64 Red Hat Enterprise Linux High Availability for x86_64 - Extended Update Support Extension 8.8 x86_64 Fixes BZ - 2446765 - CVE-2026-31958 tornado-python: Tornado: Denial of Service via large multipart bodies BZ - 2453496 - CVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template imports CVEs CVE-2026-4800 CVE-2026-31958 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 8.8 SRPM pcs-0.10.15-4.el8_8.11.src.rpm SHA-256: 9b03d5ec9760d4d530c6d42d9f47642f80a5e7af721252416695ba2e15fc3ff9 ppc64le pcs-0.10.15-4.el8_8.11.ppc64le.rpm SHA-256: 9a2a8f1b64b7dd335be4f9a808a2e335bfa742ab58414064e979de047f257f29 pcs-snmp-0.10.15-4.el8_8.11.ppc64le.rpm SHA-256: 550114f41de53fa9f932310c8c9b1621644c8ca374d3b8ff51f0149c1325e9fe Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions 8.8 SRPM pcs-0.10.15-4.el8_8.11.src.rpm SHA-256: 9b03d5ec9760d4d530c6d42d9f47642f80a5e7af721252416695ba2e15fc3ff9 x86_64 pcs-0.10.15-4.el8_8.11.x86_64.rpm SHA-256: 77ed5a25ba4994b9fa9183f5f6a6ffb79bac9a4a0e5164138a4dfd843deb0089 pcs-snmp-0.10.15-4.el8_8.11.x86_64.rpm SHA-256: 16564616efba4f0e7d198de1469a97f1edc3d27de5f098a6cdc5f9ce9fbb79ae Red Hat Enterprise Linux High Availability for x86_64 - Telecommunications Update Service 8.8 SRPM pcs-0.10.15-4.el8_8.11.src.rpm SHA-256: 9b03d5ec9760d4d530c6d42d9f47642f80a5e7af721252416695ba2e15fc3ff9 x86_64 pcs-0.10.15-4.el8_8.11.x86_64.rpm SHA-256: 77ed5a25ba4994b9fa9183f5f6a6ffb79bac9a4a0e5164138a4dfd843deb0089 pcs-snmp-0.10.15-4.el8_8.11.x86_64.rpm SHA-256: 16564616efba4f0e7d198de1469a97f1edc3d27de5f098a6cdc5f9ce9fbb79ae Red Hat Enterprise Linux High Availability for x86_64 - Extended Update Support Extension 8.8 SRPM pcs-0.10.15-4.el8_8.11.src.rpm SHA-256: 9b03d5ec9760d4d530c6d42d9f47642f80a5e7af721252416695ba2e15fc3ff9 x86_64 pcs-0.10.15-4.el8_8.11.x86_64.rpm SHA-256: 77ed5a25ba4994b9fa9183f5f6a6ffb79bac9a4a0e5164138a4dfd843deb0089 pcs-snmp-0.10.15-4.el8_8.11.x86_64.rpm SHA-256: 16564616efba4f0e7d198de1469a97f1edc3d27de5f098a6cdc5f9ce9fbb79ae The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article