RHSA-2026:50653: Important: fence-agents security update
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): httplib2: httplib2: Denial of Service via unbounded decompression of HTTP response bodies (CVE-2026-59939) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/fence-agentsto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-commonto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-computeto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-debugsourceto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-ibm-powervsto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-ibm-vpcto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-kubevirtto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-kubevirt-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-virshto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virt-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtdto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-cpgto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-cpg-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-libvirtto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-libvirt-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-multicastto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-multicast-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-serialto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-serial-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-tcpto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-virtd-tcp-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/ha-cloud-support-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-allto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-amt-wsto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-apcto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-apc-snmpto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-bladecenterto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-brocadeto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-cisco-mdsto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-cisco-ucsto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-drac5to a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-eaton-snmpto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-emersonto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-epsto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-heuristics-pingto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-hpbladeto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-ibmbladeto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-ifmibto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-ilo-moonshotto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-ilo-mpto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-ilo-sshto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-ilo2to a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-intelmodularto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-ipduto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-ipmilanto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-kdumpto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-lparto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-mpathto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-nutanix-ahvto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-openstackto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-redfishto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-rhevmto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-rsato a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-rsbto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-sbdto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-scsito a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-vmware-restto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-vmware-soapto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-wtito a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/ha-cloud-supportto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-aliyunto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-awsto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-azure-armto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-gceto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
redhat/fence-agents-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24.aa - Upgrade
Upgrade
redhat/fence-agents-debugsourceto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24.aa - Upgrade
Upgrade
redhat/fence-agents-kdump-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24.aa - Upgrade
Upgrade
redhat/fence-agents-kubevirtto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24.aa - Upgrade
Upgrade
redhat/fence-agents-kubevirt-debuginfoto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24.aa - Upgrade
Upgrade
redhat/fence-agents-allto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24.aa - Upgrade
Upgrade
redhat/fence-agents-kdumpto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24.aa - Upgrade
Upgrade
redhat/fence-agents-redfishto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24.aa - Upgrade
Upgrade
redhat/fence-agents-zvmto a version that resolves this vulnerability.Fixed in 4.10.0-43.el9_2.24 - Upgrade
Upgrade
httplib2to a version that resolves this vulnerability.Patch CVE-2026-59939
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:50653?
RHSA-2026:50653 is classified as an important security update.
How do I fix RHSA-2026:50653?
To fix RHSA-2026:50653, update the affected fence-agents packages to their latest versions.
What does RHSA-2026:50653 address?
RHSA-2026:50653 addresses a Denial of Service vulnerability via unbounded decompression in httplib2.
Which packages are affected by RHSA-2026:50653?
Affected packages include fence-agents-debuginfo, fence-agents-debugsource, fence-agents-kdump, and others.
Is it safe to use systems with RHSA-2026:50653 unpatched?
Using systems with the unpatched RHSA-2026:50653 may expose them to Denial of Service attacks.