RHSA-2025:8291: Important: pcs security update
Published May 29, 2025
·Updated
Important: pcs security update
Affected Software
15 affected componentsFixes available
Red Hat Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions
Red Hat Red Hat Enterprise Linux Resilient Storage for IBM z Systems - 4 years of updates
Red Hat Red Hat Enterprise Linux High Availability for ARM 64 - 4 years of updates
Red Hat Red Hat Enterprise Linux High Availability for IBM z Systems - 4 years of updates
Red Hat Red Hat Enterprise Linux Resilient Storage for x86_64 - 4 years of updates
Red Hat Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions
Red Hat Red Hat Enterprise Linux Resilient Storage for Power, little endian - 4 years of updates
redhat/pcs<0.11.1-10.el9_0.8
0.11.1-10.el9_0.8
redhat/pcs<0.11.1-10.el9_0.8
0.11.1-10.el9_0.8
redhat/pcs-snmp<0.11.1-10.el9_0.8
0.11.1-10.el9_0.8
redhat/pcs<0.11.1-10.el9_0.8
0.11.1-10.el9_0.8
redhat/pcs-snmp<0.11.1-10.el9_0.8
0.11.1-10.el9_0.8
redhat/pcs<0.11.1-10.el9_0.8.aa
0.11.1-10.el9_0.8.aa
redhat/pcs-snmp<0.11.1-10.el9_0.8.aa
0.11.1-10.el9_0.8.aa
redhat/pcs-snmp<0.11.1-10.el9_0.8
0.11.1-10.el9_0.8
Remediation
Event History
May 29, 2025
Advisory Published
via Red Hat·06:05 AM
Jun 18, 2025
Advisory Published
via Red Hat·06:37 AM
Data Sourced
via Red Hat·06:37 AM
RemedyDescriptionAffected Software
Frequently Asked Questions
1
What is the severity of RHSA-2025:8291?
RHSA-2025:8291 is classified as important due to the potential for denial of service and other impacts.
2
How do I fix RHSA-2025:8291?
To remediate RHSA-2025:8291, update the pcs and pcs-snmp packages to version 0.11.1-10.el9_0.8 or later.
3
What vulnerabilities are addressed in RHSA-2025:8291?
RHSA-2025:8291 addresses CVE-2025-46727 related to an unbounded-parameter denial of service in Rack::QueryParser.
4
Which packages are affected by RHSA-2025:8291?
The affected packages include pcs and pcs-snmp, specifically version 0.11.1-10.el9_0.8.
5
What action should I take if I use pcs in a production environment regarding RHSA-2025:8291?
If pcs is used in a production environment, apply the security update to mitigate the associated risks immediately.