RHSA-2025:3109: Important: pcs security update
Important: pcs security update
Other sources
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.Security Fix(es): python-tornado: Tornado has HTTP cookie parsing DoS vulnerability (CVE-2024-52804) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:3109?
The severity of RHSA-2025:3109 is classified as important.
What vulnerabilities are addressed in RHSA-2025:3109?
RHSA-2025:3109 addresses a DoS vulnerability in the python-tornado package identified by CVE-2024-52804.
How do I fix RHSA-2025:3109?
To fix RHSA-2025:3109, update the pcs and pcs-snmp packages to version 0.10.15-4.el8_8.4.
Which versions are affected by RHSA-2025:3109?
Affected versions of the pcs and pcs-snmp packages are any versions prior to 0.10.15-4.el8_8.4.
What systems are impacted by RHSA-2025:3109?
RHSA-2025:3109 impacts Red Hat Enterprise Linux High Availability and Resilient Storage products.