-------------------------------------------------------------------------Debian LTS Advisory DLA-2447-2                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                      Markus Koschany
November 17, 2020                             https://wiki.debian.org/LTS
-------------------------------------------------------------------------Package        : pacemaker
Version        : 1.1.16-1+deb9u2
Debian Bug     : 974563

The update of pacemaker released as DLA-2447-1 caused a regression when the
communication between the Corosync cluster engine and pacemaker takes place. A
permission problem prevents IPC requests between cluster nodes. The patch for
CVE-2020-25654 has been reverted until a better solution can be found.

For Debian 9 stretch, this problem has been fixed in version
1.1.16-1+deb9u2.

We recommend that you upgrade your pacemaker packages.

For the detailed security status of pacemaker please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/pacemaker

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-2447-2: pacemaker regression update

November 17, 2020
The update of pacemaker released as DLA-2447-1 caused a regression when the communication between the Corosync cluster engine and pacemaker takes place

Summary

We recommend that you upgrade your pacemaker packages.

For the detailed security status of pacemaker please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/pacemaker

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
-------------------------------------------------------------------------Package : pacemaker
Version : 1.1.16-1+deb9u2
Debian Bug : 974563

Related News