- What: Security update for pcs in Red Hat Enterprise Linux 9
- Impact: Systems using the affected pcs version may be vulnerable to arbitrary code execution via untrusted input in template imports
Red Hat Product Errata RHSA-2026:19167 - Security Advisory Issued: 2026-05-19 Updated: 2026-05-19 RHSA-2026:19167 - Security Advisory Overview Updated Packages Synopsis Important: pcs security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for pcs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. Security Fix(es): lodash: lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux High Availability for x86_64 9 x86_64 Red Hat Enterprise Linux High Availability for ARM 64 9 aarch64 Red Hat Enterprise Linux High Availability for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux Resilient Storage for x86_64 9 x86_64 Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux Resilient Storage for IBM z Systems 9 s390x Red Hat Enterprise Linux High Availability for IBM z Systems 9 s390x Red Hat Enterprise Linux Resilient Storage for Power, little endian 9 ppc64le Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux High Availability for Power, little endian 9 ppc64le Red Hat Enterprise Linux High Availability for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux High Availability (for IBM z Systems) - Extended Update Support 9.8 s390x Red Hat Enterprise Linux High Availability (for ARM 64) - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux High Availability for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux High Availability for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - 4 years of updates 9.8 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - 4 years of updates 9.8 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux High Availability for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux High Availability for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux High Availability for IBM z Systems - Extended Life Cycle 9.8 s390x Red Hat Enterprise Linux High Availability for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Life Cycle 9.8 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Life Cycle 9.8 x86_64 Fixes BZ - 2453496 - CVE-2026-4800 lodash: lodash: Arbitrary code execution via untrusted input in template imports CVEs CVE-2026-4800 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux High Availability for x86_64 9 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 x86_64 pcs-0.11.11-2.el9_8.1.x86_64.rpm SHA-256: 43bc69af3ed315c7c13aac9bddb06a1cf4189ce2d90527a6c146a8eaefa5d376 pcs-snmp-0.11.11-2.el9_8.1.x86_64.rpm SHA-256: 3f0aa578c4cb2f046a3ea4662da79a84417707fad5f12e5b5d0d7ede7e02c4c5 Red Hat Enterprise Linux High Availability for ARM 64 9 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 aarch64 pcs-0.11.11-2.el9_8.1.aarch64.rpm SHA-256: a0a7cd3ef4c351ba069b7cdd92da73d7608c4379950dbe1b87e9c482c234796b pcs-snmp-0.11.11-2.el9_8.1.aarch64.rpm SHA-256: 6cce0d2f1a73997e428d34bebddc6950b0618bc3819777d9642cf0c23474552a Red Hat Enterprise Linux High Availability for x86_64 - Extended Update Support 9.8 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 x86_64 pcs-0.11.11-2.el9_8.1.x86_64.rpm SHA-256: 43bc69af3ed315c7c13aac9bddb06a1cf4189ce2d90527a6c146a8eaefa5d376 pcs-snmp-0.11.11-2.el9_8.1.x86_64.rpm SHA-256: 3f0aa578c4cb2f046a3ea4662da79a84417707fad5f12e5b5d0d7ede7e02c4c5 Red Hat Enterprise Linux Resilient Storage for x86_64 9 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 x86_64 pcs-0.11.11-2.el9_8.1.x86_64.rpm SHA-256: 43bc69af3ed315c7c13aac9bddb06a1cf4189ce2d90527a6c146a8eaefa5d376 pcs-snmp-0.11.11-2.el9_8.1.x86_64.rpm SHA-256: 3f0aa578c4cb2f046a3ea4662da79a84417707fad5f12e5b5d0d7ede7e02c4c5 Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Update Support 9.8 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 x86_64 pcs-0.11.11-2.el9_8.1.x86_64.rpm SHA-256: 43bc69af3ed315c7c13aac9bddb06a1cf4189ce2d90527a6c146a8eaefa5d376 pcs-snmp-0.11.11-2.el9_8.1.x86_64.rpm SHA-256: 3f0aa578c4cb2f046a3ea4662da79a84417707fad5f12e5b5d0d7ede7e02c4c5 Red Hat Enterprise Linux Resilient Storage for IBM z Systems 9 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 s390x pcs-0.11.11-2.el9_8.1.s390x.rpm SHA-256: 086397281b803743a3f86d5cce09176729c7d2e7b3b7aa249aaa0fbfeb94fa17 pcs-snmp-0.11.11-2.el9_8.1.s390x.rpm SHA-256: 16163b8fa574cb576271ff0393e44eb8820f16456ff29f8b9d5eb2e5aba1e01c Red Hat Enterprise Linux High Availability for IBM z Systems 9 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 s390x pcs-0.11.11-2.el9_8.1.s390x.rpm SHA-256: 086397281b803743a3f86d5cce09176729c7d2e7b3b7aa249aaa0fbfeb94fa17 pcs-snmp-0.11.11-2.el9_8.1.s390x.rpm SHA-256: 16163b8fa574cb576271ff0393e44eb8820f16456ff29f8b9d5eb2e5aba1e01c Red Hat Enterprise Linux Resilient Storage for Power, little endian 9 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 ppc64le pcs-0.11.11-2.el9_8.1.ppc64le.rpm SHA-256: 4075c6a58d81e4d0f417be5a9ecf49e1c827bf355c32b84cb49ed56d5028852b pcs-snmp-0.11.11-2.el9_8.1.ppc64le.rpm SHA-256: 04f20987d57a8c43120b9cafc31594c66d4e04ec194a61ba646ee9a2986b96ed Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Update Support 9.8 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 ppc64le pcs-0.11.11-2.el9_8.1.ppc64le.rpm SHA-256: 4075c6a58d81e4d0f417be5a9ecf49e1c827bf355c32b84cb49ed56d5028852b pcs-snmp-0.11.11-2.el9_8.1.ppc64le.rpm SHA-256: 04f20987d57a8c43120b9cafc31594c66d4e04ec194a61ba646ee9a2986b96ed Red Hat Enterprise Linux High Availability for Power, little endian 9 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 ppc64le pcs-0.11.11-2.el9_8.1.ppc64le.rpm SHA-256: 4075c6a58d81e4d0f417be5a9ecf49e1c827bf355c32b84cb49ed56d5028852b pcs-snmp-0.11.11-2.el9_8.1.ppc64le.rpm SHA-256: 04f20987d57a8c43120b9cafc31594c66d4e04ec194a61ba646ee9a2986b96ed Red Hat Enterprise Linux High Availability for Power, little endian - Extended Update Support 9.8 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 ppc64le pcs-0.11.11-2.el9_8.1.ppc64le.rpm SHA-256: 4075c6a58d81e4d0f417be5a9ecf49e1c827bf355c32b84cb49ed56d5028852b pcs-snmp-0.11.11-2.el9_8.1.ppc64le.rpm SHA-256: 04f20987d57a8c43120b9cafc31594c66d4e04ec194a61ba646ee9a2986b96ed Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 9.8 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 ppc64le pcs-0.11.11-2.el9_8.1.ppc64le.rpm SHA-256: 4075c6a58d81e4d0f417be5a9ecf49e1c827bf355c32b84cb49ed56d5028852b pcs-snmp-0.11.11-2.el9_8.1.ppc64le.rpm SHA-256: 04f20987d57a8c43120b9cafc31594c66d4e04ec194a61ba646ee9a2986b96ed Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions 9.8 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 x86_64 pcs-0.11.11-2.el9_8.1.x86_64.rpm SHA-256: 43bc69af3ed315c7c13aac9bddb06a1cf4189ce2d90527a6c146a8eaefa5d376 pcs-snmp-0.11.11-2.el9_8.1.x86_64.rpm SHA-256: 3f0aa578c4cb2f046a3ea4662da79a84417707fad5f12e5b5d0d7ede7e02c4c5 Red Hat Enterprise Linux High Availability (for IBM z Systems) - Extended Update Support 9.8 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-256: 819f64aea2d5a5b8af5106c9bad7f115a032330eac12b71d80c4c0ae6110bd06 s390x pcs-0.11.11-2.el9_8.1.s390x.rpm SHA-256: 086397281b803743a3f86d5cce09176729c7d2e7b3b7aa249aaa0fbfeb94fa17 pcs-snmp-0.11.11-2.el9_8.1.s390x.rpm SHA-256: 16163b8fa574cb576271ff0393e44eb8820f16456ff29f8b9d5eb2e5aba1e01c Red Hat Enterprise Linux High Availability (for ARM 64) - Extended Update Support 9.8 SRPM pcs-0.11.11-2.el9_8.1.src.rpm SHA-25