RHSA-2026:58822: Important: fence-agents security update
Important: fence-agents security update
Other sources
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values (CVE-2026-59886) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/fence-agentsto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-allto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-amt-wsto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-apcto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-apc-snmpto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-bladecenterto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-brocadeto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-cisco-mdsto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-cisco-ucsto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-commonto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-computeto a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
redhat/fence-agents-drac5to a version that resolves this vulnerability.Fixed in 4.2.1-112.el8_8.21 - Upgrade
Upgrade
pyasn1to a version that resolves this vulnerability.Patch CVE-2026-59886
Event History
Frequently Asked Questions
Which systems are in scope for this update?
The advisory covers the fence-agents package collection on the listed Red Hat Enterprise Linux x86_64 and Power LE offerings, including High Availability, Update Services for SAP Solutions, TUS, and Extended Life Cycle Long Life variants.
What component is affected by the reported flaw?
The reported issue is CVE-2026-59886 in pyasn1. The stated impact is denial of service through crafted ASN.1 REAL values.
Why could this matter in a cluster environment?
fence-agents provides remote power-management scripts that can forcibly restart failed or unreachable nodes and remove them from a cluster. A denial-of-service condition affecting its dependency may be operationally significant where these agents are used for cluster fencing.