RHSA-2025:2470: Important: pcs security update
Important: pcs security update
Other sources
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.Security Fix(es): python-tornado: Tornado has HTTP cookie parsing DoS vulnerability (CVE-2024-52804) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:2470?
The severity of RHSA-2025:2470 is classified as important.
How do I fix RHSA-2025:2470?
To fix RHSA-2025:2470, update the pcs package to version 0.11.7-2.el9_4.3 or later.
What does RHSA-2025:2470 address?
RHSA-2025:2470 addresses a Denial of Service vulnerability in the python-tornado package.
Which packages are affected by RHSA-2025:2470?
The affected packages in RHSA-2025:2470 include pcs and pcs-snmp.
Is there a specific version required to mitigate RHSA-2025:2470?
Yes, version 0.11.7-2.el9_4.3 is required to mitigate the vulnerabilities detailed in RHSA-2025:2470.