AlmaLinux / AlmaLinux/updates

Release pcs-0.11.9-2.el9_6.2 ALSA-2025:19512

Open
#1,893 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
2
Forks
0
PR merge metrics
No merged PRs in 30d

Description

pcs security update
Severity: Important
Description
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.

Security Fix(es):

* rubygem-rack: Rack QueryParser has an unsafe default allowing params_limit bypass via semicolon-separated parameters (CVE-2025-59830)
* rack: Rack's unbounded multipart preamble buffering enables DoS (memory exhaustion) (CVE-2025-61770)
* rack: Rack's multipart parser buffers large non?file fields entirely in memory, enabling DoS (memory exhaustion) (CVE-2025-61771)
* rack: Rack memory exhaustion denial of service (CVE-2025-61772)
* rubygem-rack: Unbounded read in `Rack::Request` form parsing can lead to memory exhaustion (CVE-2025-61919)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected packages:
pcs-0.11.9-2.el9_6.2.x86_64
pcs-snmp-0.11.9-2.el9_6.2.x86_64
pcs-0.11.9-2.el9_6.2.s390x
pcs-snmp-0.11.9-2.el9_6.2.s390x
pcs-0.11.9-2.el9_6.2.ppc64le
pcs-snmp-0.11.9-2.el9_6.2.ppc64le

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.