Red Hat Product Errata RHSA-2026:19138 - Security Advisory Issued: 2026-05-19 Updated: 2026-05-19 RHSA-2026:19138 - Security Advisory Overview Updated Packages Synopsis Important: fence-agents security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for fence-agents is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597) pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2447194 - CVE-2026-32597 pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) BZ - 2448553 - CVE-2026-30922 pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion CVEs CVE-2026-30922 CVE-2026-32597 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM fence-agents-4.16.0-21.el10_2.1.src.rpm SHA-256: 9637eb536bd2b99345b20a5f51baccc1376d781bc17394dd54eb859dace0ea75 x86_64 fence-agents-aliyun-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: ca852e40c2502d6bd96deb122907c697d56d6173983637abc278d5fd2ff80c69 fence-agents-all-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 5b6766703fdbbf16035eb31f33d601b7539bec80481fa2917acd47369f2120a9 fence-agents-amt-ws-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 2437db8b1fd29c7315c82e5383f34b834db30f1138f225b93581ac90a886d5ad fence-agents-apc-4.16.0-21.el10_2.1.noarch.rpm SHA-256: cfb216ee01e882ebd5a5b0c4f564546ddaa8fa1533ba87eba8abec9490488798 fence-agents-apc-snmp-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 801c1dc5f302d6bae8b7fcc0de8f0f0f6b1f2294ba16c2b8fc7d9aa1cf6ee8a4 fence-agents-aws-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: e451f5f8650b8a7bcc7937699650e76a0f8a30f468fde0eaaef3db1bb25efbfb fence-agents-azure-arm-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 3913ab931126811a52d4001fb27a8193cc4cb5de02925ad90e55a92a31b90a46 fence-agents-bladecenter-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 5a66227ebe75ccc82c719a1159ab9d41303546a6306d5e6c14b753e2cfcbcf37 fence-agents-brocade-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 617cb64d51f94459b7d92c566e65eeeca01c7cee0bcd62233053b8b7a5a89c52 fence-agents-cisco-mds-4.16.0-21.el10_2.1.noarch.rpm SHA-256: da6f630b64682d59c0daa546c02ec8d8587da56d9e06621dfdd20d1ce30c78b9 fence-agents-cisco-ucs-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 68cfc20d6dd5cb15dc18d6e32f89b5830547fd3a4fac647ca266b13386fd1264 fence-agents-common-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 630a0053e40cede584f9375d932cc5db6813cf3e26e061f8d6ca29ab152e9ce7 fence-agents-common-debuginfo-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 3ae1968f9c8427768d19b9833105c1028cce5044735fdc4e19e9cd72d4de82b6 fence-agents-debuginfo-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 6251bcaa4f199e23c5812ed49a0222c33361167b89ca730964a40d361d66e00d fence-agents-debugsource-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 7f75204a87f2c3b201e0d4d8d855138d75741be159c7ae844e324c95ae7ba8ee fence-agents-drac5-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 4fb675449c56133cd7cef0f2f6a8fb7914d667c2e23ea462be1be957f7384892 fence-agents-eaton-snmp-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 2866a9c89898570b7260df3b4abfd39f3f7cd90a7b0ce6e6b70008c50c5845e1 fence-agents-emerson-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 398ed6687ed271484636d7920052ce443378f2c679b489c928acebce65955209 fence-agents-eps-4.16.0-21.el10_2.1.noarch.rpm SHA-256: af97729a08fabcdd4c2c93fd8340d9ccc22cad298596a8520a84ac761e414221 fence-agents-gce-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 38eb020e65d56b19e8566d5bdbcac4590cc8e66618c1086d6e05640c3099e11e fence-agents-heuristics-ping-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 45767cef21df36ef492fcc41892cf89e4d96b59bdaaa6ce0f5e3155329314ccd fence-agents-hpblade-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 208f1df11856b9ad872c2db21ebe377d9b600f38769e975da18d08f71082bcf7 fence-agents-ibm-powervs-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 7ab085c7602957632fed49557115b516a22c867962d97fd313021085215f68ff fence-agents-ibm-vpc-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 3f0d9dfd1f35c3377674b334019a430d7f00e41b7e0216b797a1d58b3781b518 fence-agents-ibmblade-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 99fd35428bbe2aaaef5c476bdf1a5b01735b8ff246bd27acb4df68cf6f95c7a7 fence-agents-ifmib-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 6685e213d50a2b1ee22aa37df41bc5664e8a18aecfcc2da167046fe25dc0861c fence-agents-ilo-moonshot-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 1eb2566ac96a0a123450e4649e9b677ceffffbdc0e1dddb43508986a2bd6475c fence-agents-ilo-mp-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 66067fa5fa8d442067a0b33b599f5a7d4b9eed9bbf3cffacb43800f3ce2475a9 fence-agents-ilo-ssh-4.16.0-21.el10_2.1.noarch.rpm SHA-256: b4fde25bd3c21dc7444ffe1b4535f8ad8e4f4a93c5d3de40c29a0f7cac5304fa fence-agents-ilo2-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 80d78b3576c8037ceb0730ad48ec41ba6a80f7378324bee88366f612b7c2febb fence-agents-intelmodular-4.16.0-21.el10_2.1.noarch.rpm SHA-256: e535e55e03fbfe2418a3db88342da80f4f75e68d35e9ec8e6341a9934d9651a3 fence-agents-ipdu-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 789a8bafbc65a2c9abe6ea11e00a48b54627f88e6a6ea23dff4d115d5f6ec72c fence-agents-ipmilan-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 34d1d7f7f501731cdb7e9b7930997ad7cbec6aeb14f6ec699df92c2ef8df9515 fence-agents-kdump-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 39bce5ce358ea72aaa10fd496bbf21964e0c1bbc12197e572bec30e5f4d8a59a fence-agents-kdump-debuginfo-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 69d3bfe38d45a90b122cf8f6ee8c7b4b48216cb58f01ace94f8eca2b79218f1f fence-agents-kubevirt-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: b97ffaf8bb3b0b3b515f61be58cf445429e1cdc6464d54b6ccfdd1d78992ca60 fence-agents-mpath-4.16.0-21.el10_2.1.noarch.rpm SHA-256: ffca2eb4c33ec1edf8d70507100680a73b5a32df95ca894696fd71089e4a1c78 fence-agents-nutanix-ahv-4.16.0-21.el10_2.1.noarch.rpm SHA-256: e8c1230824250effb601e4342c891f7715fde1160a205be2430199e5888acf29 fence-agents-openstack-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 0117e8d902dc00ee5be24da6d07ec9381b4ebc8d45b26d1d315d78dc981cf40a fence-agents-redfish-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 982c16bb130988bd47fd3bf57e6aad8377bcfc58f1c39bf5a94b0363a4b5d808 fence-agents-rhevm-4.16.0-21.el10_2.1.noarch.rpm SHA-256: d8361d2be1d069c157082aa8caec2e481830b33897a0f566f2384cac570d1b0f fence-agents-rsa-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 053b451d211d8b202789e644d4e1df2befce1f6804b3c8129c2c9c0cf522f3aa fence-agents-rsb-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 4d24c6564956d87466b4b491371eeaa08718e1b79a57c8c350223a2597fd2f56 fence-agents-sbd-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 870e5f286e1dc7fe799c80ac7ab1a95f11079e17841b921e15ca058257d6e214 fence-agents-scsi-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 99e286d399a5c0beeb34c8ff09beca0bfdafe1808866abb4f5df42f8b9e562c7 fence-agents-virsh-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 2abe3a572a4b8a1f7e798ec79b41e61425a0d12d1f429409648eb4649aa9123d fence-agents-vmware-rest-4.16.0-21.el10_2.1.noarch.rpm SHA-256: d046d9fa8094da6defa92398100e15379fed52b04f7450bf417e4b77c3a0e6d4 fence-agents-vmware-soap-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 2a530ef4208e72e7d672a6c193fe948812dc231132dceb59c603514dab528504 fence-agents-wti-4.16.0-21.el10_2.1.noarch.rpm SHA-256: 52c70dd95eb698bd2fb076a8ca96cdb53425f196a90bb12bebe6f3d25e74975d fence-virt-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 0afec0e65fa413a61a8a8e9c26235508cc3bcce72ed897890dbd31a148df5ca0 fence-virt-debuginfo-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 7071c9c8caeda76f105242a013e2ab5142f398c7c47b04ec727583b41e64e147 fence-virtd-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: be8bed22c6b8ba8d57ac57b17fd0ec856b2066f855dad3f8047c609d96357188 fence-virtd-cpg-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: ccfc623d423c29a214e17820ce8ca3a36083a322676fd558323b81de8ef82a19 fence-virtd-cpg-debuginfo-4.16.0-21.el10_2.1.x86_64.rpm SHA-256: 8f1885b036cdb30137b00b447190a5d6b191d242401582a6d38a60442a2b4c65 fence-vir
A critical update for Red Hat Enterprise Linux 10's fence-agents package addresses two high-severity vulnerabilities (CVSS 7.5) in its dependencies. The first, CVE-2026-32597 in PyJWT, is a security policy bypass where unknown `crit` header extensions are incorrectly accepted. The second, CVE-2026-30922 in pyasn1, allows denial of service via unbounded recursion. Affected systems must update the underlying libraries to PyJWT 2.12.0 and pyasn1 0.6.3, respectively.