RHSA-2025:2872: Important: pcs security update
Important: pcs security update
Other sources
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.<br>Security Fix(es):<br><li> python-tornado: Tornado has HTTP cookie parsing DoS vulnerability (CVE-2024-52804)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:2872?
RHSA-2025:2872 is classified as an important security update.
How do I fix RHSA-2025:2872?
To fix RHSA-2025:2872, update the pcs packages to version 0.10.18-2.el8_10.4 or later.
What vulnerability does RHSA-2025:2872 address?
RHSA-2025:2872 addresses a DoS vulnerability in the python-tornado HTTP cookie parsing.
Which products are affected by RHSA-2025:2872?
RHSA-2025:2872 affects various Red Hat Enterprise Linux High Availability and Resilient Storage products.
Is there a workaround for RHSA-2025:2872?
There are no official workarounds provided for RHSA-2025:2872; updating is the recommended course of action.