RHSA-2024:4400: Important: booth security update
Important: booth security update
Other sources
The Booth cluster ticket manager is a component to bridge high availability clusters spanning multiple sites, in particular, to provide decision inputs to local Pacemaker cluster resource managers. It operates as a distributed consensus-based service, presumably on a separate physical network. Tickets facilitated by a Booth formation are the units of authorization that can be bound to certain resources. This will ensure that the resources are run at only one (granted) site at a time.Security Fix(es): booth: specially crafted hash can lead to invalid HMAC being accepted by Booth server (CVE-2024-3049) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:4400?
RHSA-2024:4400 is classified as an important security update.
How do I fix RHSA-2024:4400?
To fix RHSA-2024:4400, you should update the affected packages to version 1.0-199.1.ac1d34c.git.el8_6.2.
What packages are affected by RHSA-2024:4400?
RHSA-2024:4400 affects various packages including booth, booth-arbitrator, and booth-core among others.
Is there a specific version I need to update to for RHSA-2024:4400?
Yes, you need to update to version 1.0-199.1.ac1d34c.git.el8_6.2.
What platforms does RHSA-2024:4400 affect?
RHSA-2024:4400 affects platforms including x86_64, ppc64le, and noarch.