RHSA-2025:2471: Important: pcs security update
Important: pcs security update
Other sources
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.<br>Security Fix(es):<br><li> python-tornado: Tornado has HTTP cookie parsing DoS vulnerability (CVE-2024-52804)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:2471?
The severity of RHSA-2025:2471 is classified as important.
How do I fix RHSA-2025:2471?
To fix RHSA-2025:2471, you should update the `pcs` and `pcs-snmp` packages to version 0.11.8-1.el9_5.2 or newer.
What vulnerabilities does RHSA-2025:2471 address?
RHSA-2025:2471 addresses a DoS vulnerability in the Tornado library identified as CVE-2024-52804.
Which products are affected by RHSA-2025:2471?
Affected products include various versions of Red Hat Enterprise Linux High Availability and Resilient Storage on ARM 64, x86_64, IBM z Systems, and Power architectures.
Is a reboot required after applying RHSA-2025:2471?
No, a reboot is not required after applying the update for RHSA-2025:2471.