RHSA-2026:53365: Important: fence-agents security update
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/fence-agentsto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-aliyunto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-allto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-amt-wsto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-apcto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-apc-snmpto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-awsto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-azure-armto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-bladecenterto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-brocadeto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-cisco-mdsto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-cisco-ucsto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-commonto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-computeto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-debugsourceto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-drac5to a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-eaton-snmpto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-emersonto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-epsto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-gceto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-heuristics-pingto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-hpbladeto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-ibm-powervsto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-ibm-vpcto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-ibmbladeto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-ifmibto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-ilo-moonshotto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-ilo-mpto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-ilo-sshto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-ilo2to a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-intelmodularto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-ipduto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-ipmilanto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-kdumpto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-kubevirtto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-kubevirt-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-lparto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-mpathto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-nutanix-ahvto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-openstackto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-redfishto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-rhevmto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-rsato a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-rsbto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-sbdto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-scsito a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-virshto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-vmware-restto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-vmware-soapto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-wtito a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virt-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtdto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-cpgto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-cpg-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-libvirtto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-libvirt-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-multicastto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-multicast-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-serialto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-serial-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-tcpto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-virtd-tcp-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/ha-cloud-supportto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/ha-cloud-support-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-zvmto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6 - Upgrade
Upgrade
redhat/fence-agents-allto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6.aa - Upgrade
Upgrade
redhat/fence-agents-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6.aa - Upgrade
Upgrade
redhat/fence-agents-debugsourceto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6.aa - Upgrade
Upgrade
redhat/fence-agents-kdumpto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6.aa - Upgrade
Upgrade
redhat/fence-agents-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6.aa - Upgrade
Upgrade
redhat/fence-agents-kubevirtto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6.aa - Upgrade
Upgrade
redhat/fence-agents-kubevirt-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6.aa - Upgrade
Upgrade
redhat/fence-agents-redfishto a version that resolves this vulnerability.Fixed in 4.10.0-110.el9_8.6.aa - Upgrade
Upgrade
pyasn1to a version that resolves this vulnerability.Patch CVE-2026-59886 - Compensating control
Use the fence-agents security update to ensure remote power management scripts (for forcibly restarting/removing failed or unreachable nodes from the cluster) are updated per the advisory (Red Hat article 11258).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:53365?
The severity of RHSA-2026:53365 is classified as important.
What does RHSA-2026:53365 fix?
RHSA-2026:53365 addresses a denial of service vulnerability in the pyasn1 library via crafted ASN.1 REAL values.
How do I fix RHSA-2026:53365?
To fix RHSA-2026:53365, users should update their fence-agents packages to the latest version provided by Red Hat.
Which Red Hat packages are affected by RHSA-2026:53365?
The affected Red Hat packages include fence-agents-all, fence-agents-debuginfo, fence-agents-debugsource, fence-agents-kdump, fence-agents-kubevirt, and fence-agents-redfish.
When was RHSA-2026:53365 published?
RHSA-2026:53365 was published on August 11, 2026.