RHSA-2025:8290: Important: pcs security update
Important: pcs security update
Other sources
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.Security Fix(es): rubygem-rack: Unbounded-Parameter DoS in Rack::QueryParser (CVE-2025-46727) tornado: Tornado Multipart Form-Data Denial of Service (CVE-2025-47287) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8290?
The severity of RHSA-2025:8290 is classified as important.
How do I fix RHSA-2025:8290?
To fix RHSA-2025:8290, you should update to the latest version of the pcs package.
What vulnerabilities are addressed in RHSA-2025:8290?
RHSA-2025:8290 addresses vulnerabilities including CVE-2025-46727 related to unbounded-parameter DoS in Rack::QueryParser.
Which packages are affected by RHSA-2025:8290?
The affected packages in RHSA-2025:8290 include pcs and pcs-snmp versions up to 0.10.12-6.el8_6.8.
Is RHSA-2025:8290 related to any specific software?
Yes, RHSA-2025:8290 is specifically related to the pcs command-line configuration system for the Pacemaker and Corosync utilities.