AlmaLinux / AlmaLinux/updates

Release cockpit-ha-cluster-0.12.0-3.el10_0.3 ALSA-2025:19513

未關閉
#1,789 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
沒有語言資料
星號
2
分支
0
PR 合併指標
30 天內沒有已合併 PR

描述

pcs security update
Severity: Important
Description
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.

Security Fix(es):

* rubygem-rack: Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters (CVE-2025-59830)
* rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) (CVE-2025-61770)
* rack: Rack's multipart parser buffers large non?file fields entirely in memory, enabling DoS (memory exhaustion) (CVE-2025-61771)
* rack: Rack memory exhaustion denial of service (CVE-2025-61772)
* rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion (CVE-2025-61919)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
cockpit-ha-cluster-0.12.0-3.el10_0.3.noarch
pcs-0.12.0-3.el10_0.3.x86_64
pcs-snmp-0.12.0-3.el10_0.3.x86_64
cockpit-ha-cluster-0.12.0-3.el10_0.3.noarch
pcs-0.12.0-3.el10_0.3.s390x
pcs-snmp-0.12.0-3.el10_0.3.s390x
cockpit-ha-cluster-0.12.0-3.el10_0.3.noarch
pcs-0.12.0-3.el10_0.3.ppc64le
pcs-snmp-0.12.0-3.el10_0.3.ppc64le
pcs-0.12.0-3.el10_0.3.x86_64_v2
pcs-snmp-0.12.0-3.el10_0.3.x86_64_v2
cockpit-ha-cluster-0.12.0-3.el10_0.3.noarch

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。