Release cockpit-ha-cluster-0.12.0-3.el10_0.3 ALSA-2025:19513
- Dominant language
- No language data
- Stars
- 2
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
pcs security update
Severity: Important
Description
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.
Security Fix(es):
* rubygem-rack: Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters (CVE-2025-59830)
* rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) (CVE-2025-61770)
* rack: Rack's multipart parser buffers large non?file fields entirely in memory, enabling DoS (memory exhaustion) (CVE-2025-61771)
* rack: Rack memory exhaustion denial of service (CVE-2025-61772)
* rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion (CVE-2025-61919)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected packages:
cockpit-ha-cluster-0.12.0-3.el10_0.3.noarch
pcs-0.12.0-3.el10_0.3.x86_64
pcs-snmp-0.12.0-3.el10_0.3.x86_64
cockpit-ha-cluster-0.12.0-3.el10_0.3.noarch
pcs-0.12.0-3.el10_0.3.s390x
pcs-snmp-0.12.0-3.el10_0.3.s390x
cockpit-ha-cluster-0.12.0-3.el10_0.3.noarch
pcs-0.12.0-3.el10_0.3.ppc64le
pcs-snmp-0.12.0-3.el10_0.3.ppc64le
pcs-0.12.0-3.el10_0.3.x86_64_v2
pcs-snmp-0.12.0-3.el10_0.3.x86_64_v2
cockpit-ha-cluster-0.12.0-3.el10_0.3.noarch
Contributor guide
Assessment
This issue has not been assessed yet.