RHSA-2026:42041: Important: pacemaker security update
Important: pacemaker security update
Other sources
The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures. Security Fix(es): pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pacemakerto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-cli-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-cluster-libsto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-cluster-libs-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-debugsourceto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-libsto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-libs-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-remote-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-schemasto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-clito a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-ctsto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-docto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-libs-develto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-nagios-plugins-metadatato a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
redhat/pacemaker-remoteto a version that resolves this vulnerability.Fixed in 2.1.5-9.7.el8_8 - Upgrade
Upgrade
pacemakerto a version that resolves this vulnerability.Patch CVE-2026-10649
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:42041?
The severity of RHSA-2026:42041 is rated high with a score of 7.
What vulnerability is addressed in RHSA-2026:42041?
RHSA-2026:42041 addresses a Denial of Service vulnerability caused by an integer overflow in the Pacemaker cluster resource manager.
How do I fix RHSA-2026:42041?
To fix RHSA-2026:42041, ensure that your installation of Pacemaker is updated to the latest version provided by Red Hat.
What products are affected by RHSA-2026:42041?
The affected products include redhat/pacemaker, redhat/pacemaker-cli-debuginfo, and several libraries associated with Pacemaker.
What could happen if RHSA-2026:42041 is not addressed?
If RHSA-2026:42041 is not addressed, it may lead to a Denial of Service, impacting the availability of applications managed by Pacemaker.