RHSA-2025:3108: Important: pcs security update
Important: pcs security update
Other sources
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.Security Fix(es): python-tornado: Tornado has HTTP cookie parsing DoS vulnerability (CVE-2024-52804) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:3108?
RHSA-2025:3108 has been classified as an Important security update.
What vulnerability does RHSA-2025:3108 address?
RHSA-2025:3108 addresses the HTTP cookie parsing DoS vulnerability in python-tornado (CVE-2024-52804).
How do I fix the vulnerabilities listed in RHSA-2025:3108?
To fix the vulnerabilities in RHSA-2025:3108, update the pcs and pcs-snmp packages to version 0.11.4-7.el9_2.4.
Which packages are affected by RHSA-2025:3108?
The affected packages in RHSA-2025:3108 include pcs and pcs-snmp versions prior to 0.11.4-7.el9_2.4.
Is RHSA-2025:3108 applicable to all versions of Red Hat Enterprise Linux?
RHSA-2025:3108 specifically applies to certain versions of Red Hat Enterprise Linux, including High Availability and Resilient Storage for various architectures.