A pcs security and bug fix update has been released for AlmaLinux 8.
ALSA-2023:3082 Moderate: pcs security and bug fix update
Type:
security
Severity:
moderate
Release date:
2023-05-19
Description
Security Fix(es):
* rubygem-rack: Denial of service in Multipart MIME parsing (CVE-2023-27530)
* rubygem-rack: denial of service in header parsing (CVE-2023-27539)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Command 'pcs config checkpoint diff' does not show configuration differences between checkpoints (BZ#2180700)
* Need a way to add a scsi fencing device to a cluster without requiring a restart of all cluster resources (BZ#2180706)
References:
RHSA-2023:3082
CVE-2023-27530
CVE-2023-27539
ALSA-2023:3082
Updates packages:
pcs-snmp-0.10.15-4.el8_8.1.alma.x86_64.rpm
pcs-0.10.15-4.el8_8.1.alma.x86_64.rpm
pcs-snmp-0.10.15-4.el8_8.1.alma.aarch64.rpm
pcs-0.10.15-4.el8_8.1.alma.aarch64.rpm
pcs-0.10.15-4.el8_8.1.alma.ppc64le.rpm
pcs-snmp-0.10.15-4.el8_8.1.alma.ppc64le.rpm
pcs-0.10.15-4.el8_8.1.alma.s390x.rpm
pcs-snmp-0.10.15-4.el8_8.1.alma.s390x.rpm
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.