RHSA-2026:58821: Important: fence-agents security update
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/fence-agentsto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-aliyun-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-allto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-amt-wsto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-apcto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-apc-snmpto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-bladecenterto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-brocadeto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-cisco-mdsto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-cisco-ucsto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-commonto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-computeto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-debugsourceto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-drac5to a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-eaton-snmpto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-emersonto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-epsto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-heuristics-pingto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-hpbladeto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-ibmbladeto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-ifmibto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-ilo-moonshotto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-ilo-mpto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-ilo-sshto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-ilo2to a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-intelmodularto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-ipduto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-ipmilanto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-kdumpto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-kubevirt-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-lparto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-mpathto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-redfishto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-rhevmto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-rsato a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-rsbto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-sbdto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-scsito a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-virshto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-vmware-restto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-vmware-soapto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-wtito a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-ibm-powervsto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-ibm-vpcto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-kubevirtto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-nutanix-ahvto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-aliyunto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-awsto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-azure-armto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
redhat/fence-agents-gceto a version that resolves this vulnerability.Fixed in 4.2.1-65.el8_4.32 - Upgrade
Upgrade
pyasn1to a version that resolves this vulnerability.Patch CVE-2026-59886 - Compensating control
Apply the fence-agents security update for the fence-agents packages (remote power management scripts) that can forcibly restart and remove failed/unreachable nodes from the cluster.