Explore top 10 tips to secure your open-source projects now. Read More
×
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-39323 http://linux.oracle.com/errata/ELSA-2026-39323.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: pacemaker-cluster-libs-2.1.10-3.0.1.el9_8.i686.rpm pacemaker-cluster-libs-2.1.10-3.0.1.el9_8.x86_64.rpm pacemaker-libs-2.1.10-3.0.1.el9_8.i686.rpm pacemaker-libs-2.1.10-3.0.1.el9_8.x86_64.rpm pacemaker-schemas-2.1.10-3.0.1.el9_8.noarch.rpm aarch64: pacemaker-cluster-libs-2.1.10-3.0.1.el9_8.aarch64.rpm pacemaker-libs-2.1.10-3.0.1.el9_8.aarch64.rpm pacemaker-schemas-2.1.10-3.0.1.el9_8.noarch.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/pacemaker-2.1.10-3.0.1.el9_8.src.rpm Related CVEs: CVE-2026-10649 Description of changes: [2.1.10-3.0.1] - Replace bug url [Orabug: 34202300] - Upstream reference in pacemaker crm_report binary [Orabug: 32825154] [2.1.10-3] - Fix integer overflows in remote message decompression code (CVE-2026-10649) - Resolves: RHEL-181150 _______________________________________________ El-errata mailing list
Important: pacemaker security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39323", "synopsis": "Important: pacemaker security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pacemaker.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures. \n\nSecurity Fix(es):\n\n* pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2462817", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2462817", "description": ""}], "cves": [{"name": "CVE-2026-10649", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-10649", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", "cvss3BaseScore": "8.6", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-07-15T12:03:43.176942Z", "rpms": {"Rocky Linux 9": {"nvras": ["pacemaker-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-0:2.1.10-3.el9_8.src.rpm", "pacemaker-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-cli-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-cli-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-cli-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-cli-debuginfo-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-cli-debuginfo-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-cli-debuginfo-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-cluster-libs-0:2.1.10-3.el9_8.aarch64.rpm","pacemaker-cluster-libs-0:2.1.10-3.el9_8.i686.rpm", "pacemaker-cluster-libs-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-cluster-libs-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-cluster-libs-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-cluster-libs-debuginfo-0:2.1.10-3.el9_8.aarch64.rpm", "pacemaker-cluster-libs-debuginfo-0:2.1.10-3.el9_8.i686.rpm", "pacemaker-cluster-libs-debuginfo-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-cluster-libs-debuginfo-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-cluster-libs-debuginfo-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-cts-0:2.1.10-3.el9_8.noarch.rpm", "pacemaker-debuginfo-0:2.1.10-3.el9_8.aarch64.rpm", "pacemaker-debuginfo-0:2.1.10-3.el9_8.i686.rpm", "pacemaker-debuginfo-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-debuginfo-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-debuginfo-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-debugsource-0:2.1.10-3.el9_8.aarch64.rpm", "pacemaker-debugsource-0:2.1.10-3.el9_8.i686.rpm", "pacemaker-debugsource-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-debugsource-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-debugsource-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-doc-0:2.1.10-3.el9_8.noarch.rpm", "pacemaker-libs-0:2.1.10-3.el9_8.aarch64.rpm", "pacemaker-libs-0:2.1.10-3.el9_8.i686.rpm", "pacemaker-libs-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-libs-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-libs-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-libs-debuginfo-0:2.1.10-3.el9_8.aarch64.rpm", "pacemaker-libs-debuginfo-0:2.1.10-3.el9_8.i686.rpm", "pacemaker-libs-debuginfo-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-libs-debuginfo-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-libs-debuginfo-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-libs-devel-0:2.1.10-3.el9_8.i686.rpm", "pacemaker-libs-devel-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-libs-devel-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-libs-devel-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-nagios-plugins-metadata-0:2.1.10-3.el9_8.noarch.rpm", "pacemaker-remote-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-remote-0:2.1.10-3.el9_8.s390x.rpm","pacemaker-remote-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-remote-debuginfo-0:2.1.10-3.el9_8.ppc64le.rpm", "pacemaker-remote-debuginfo-0:2.1.10-3.el9_8.s390x.rpm", "pacemaker-remote-debuginfo-0:2.1.10-3.el9_8.x86_64.rpm", "pacemaker-schemas-0:2.1.10-3.el9_8.noarch.rpm", "python3-pacemaker-0:2.1.10-3.el9_8.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Pacemaker security update addresses a DoS risk on Rocky Linux 9 related to integer overflow issue. Details inside.. Rocky Linux, pacemaker, Denial of Service, security update, integer overflow. . Severity: Important. LinuxSecurity.com Team
Important: pacemaker security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39322", "synopsis": "Important: pacemaker security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for pacemaker.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures. \n\nSecurity Fix(es):\n\n* pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2462817", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2462817", "description": ""}], "cves": [{"name": "CVE-2026-10649", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-10649", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H", "cvss3BaseScore": "8.6", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-07-15T12:01:08.928069Z", "rpms": {"Rocky Linux 8": {"nvras": ["pacemaker-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-0:2.1.7-5.6.el8_10.src.rpm", "pacemaker-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-cli-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-cli-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-cli-debuginfo-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-cli-debuginfo-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-cluster-libs-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-cluster-libs-0:2.1.7-5.6.el8_10.i686.rpm", "pacemaker-cluster-libs-0:2.1.7-5.6.el8_10.x86_64.rpm","pacemaker-cluster-libs-debuginfo-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-cluster-libs-debuginfo-0:2.1.7-5.6.el8_10.i686.rpm", "pacemaker-cluster-libs-debuginfo-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-cts-0:2.1.7-5.6.el8_10.noarch.rpm", "pacemaker-debuginfo-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-debuginfo-0:2.1.7-5.6.el8_10.i686.rpm", "pacemaker-debuginfo-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-debugsource-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-debugsource-0:2.1.7-5.6.el8_10.i686.rpm", "pacemaker-debugsource-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-doc-0:2.1.7-5.6.el8_10.noarch.rpm", "pacemaker-libs-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-libs-0:2.1.7-5.6.el8_10.i686.rpm", "pacemaker-libs-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-libs-debuginfo-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-libs-debuginfo-0:2.1.7-5.6.el8_10.i686.rpm", "pacemaker-libs-debuginfo-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-libs-devel-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-libs-devel-0:2.1.7-5.6.el8_10.i686.rpm", "pacemaker-libs-devel-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-nagios-plugins-metadata-0:2.1.7-5.6.el8_10.noarch.rpm", "pacemaker-remote-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-remote-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-remote-debuginfo-0:2.1.7-5.6.el8_10.aarch64.rpm", "pacemaker-remote-debuginfo-0:2.1.7-5.6.el8_10.x86_64.rpm", "pacemaker-schemas-0:2.1.7-5.6.el8_10.noarch.rpm", "python3-pacemaker-0:2.1.7-5.6.el8_10.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Find details about the important pacemaker security update for Rocky Linux, addressing a critical integer overflow issue.. pacemaker security update, Rocky Linux advisory, denial of service security, important security patching. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for pacemaker Announcement ID: SUSE-SU-2026:22510-1 Release Date: 2026-06-29T10:55:21Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issues: * CVE-2026-10649: Fixed denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1108=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * pacemaker-remote-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-remote-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cli-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-debugsource-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-libs-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cli-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-devel-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-libs-3.0.0+20250218.64cd85422c-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * pacemaker-schemas-3.0.0+20250218.64cd85422c-160000.4.1 *python3-pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cts-3.0.0+20250218.64cd85422c-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 . This important advisory addresses a denial of service risk in pacemaker for SUSE, offering critical update guidance.. SUSE pacemaker update security patch important. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for pacemaker Announcement ID: SUSE-SU-2026:2742-1 Release Date: 2026-07-03T09:20:51Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issue * CVE-2026-10649: denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-2742=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2742=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * pacemaker-remote-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker-devel-2.1.2+20211124.ada5c3b36-150400.4.39.1 *pacemaker-remote-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debugsource-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * openSUSE Leap 15.4 (noarch) * pacemaker-cts-2.1.2+20211124.ada5c3b36-150400.4.39.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * pacemaker-remote-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debugsource-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker-devel-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-remote-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-2.1.2+20211124.ada5c3b36-150400.4.39.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (noarch) * pacemaker-cts-2.1.2+20211124.ada5c3b36-150400.4.39.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 . # Security update for pacemaker Announcement ID: SUSE-SU-2026:2742-1 Release Date: 2026-07-03T09:20:. update, solves, vulnerability, installed, security, pacemaker, announ. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for pacemaker Announcement ID: SUSE-SU-2026:2742-1 Release Date: 2026-07-03T09:20:51Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issue * CVE-2026-10649: denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-2742=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2742=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * pacemaker-remote-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker-devel-2.1.2+20211124.ada5c3b36-150400.4.39.1 *pacemaker-remote-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debugsource-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * openSUSE Leap 15.4 (noarch) * pacemaker-cts-2.1.2+20211124.ada5c3b36-150400.4.39.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * pacemaker-remote-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debugsource-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker-devel-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-remote-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-2.1.2+20211124.ada5c3b36-150400.4.39.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (noarch) * pacemaker-cts-2.1.2+20211124.ada5c3b36-150400.4.39.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 . SUSE releases an important update for pacemaker fixing a denial of service through integer overflow. Install now.. SUSE pacemaker update important security. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for pacemaker ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21196-1 Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for pacemaker fixes the following issues: - CVE-2026-10649: Fixed denial of service via integer overflow in remote message decompression (bsc#1268381). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1108=1 Package List: - openSUSE Leap 16.0: pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 pacemaker-cli-3.0.0+20250218.64cd85422c-160000.4.1 pacemaker-cts-3.0.0+20250218.64cd85422c-160000.4.1 pacemaker-devel-3.0.0+20250218.64cd85422c-160000.4.1 pacemaker-libs-3.0.0+20250218.64cd85422c-160000.4.1 pacemaker-remote-3.0.0+20250218.64cd85422c-160000.4.1 pacemaker-schemas-3.0.0+20250218.64cd85422c-160000.4.1 python3-pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 References: * https://www.suse.com/security/cve/CVE-2026-10649.html . This openSUSE advisory details a critical update for pacemaker addressing an important denial of service issue. Immediate action is recommended.. openSUSE pacemaker update, denial of service fix, important security advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for pacemaker Announcement ID: SUSE-SU-2026:2719-1 Release Date: 2026-07-01T11:33:19Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issues: * CVE-2026-10649: Fixed denial-of-service via integer overflow in remote message decompression (bsc#1268381). Changes for pacemaker: * Update to version 2.1.10+20260618.4bca25e3c1: * libcrmcommon: Add additional checks to pcmk__remote_message_xml. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcib: Remove an unnecessary coverity suppression. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Fix an integer overflow in pcmk__remote_send_xml. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Limit the max size of a remote message. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Fix integer overflow in remote message code. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Add sanity checks to localized_remote_header. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Fix a glib logging build error * libcrmcommon, libpacemaker: Don't assign const char * to char * ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSELinux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-2719=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * pacemaker-cli-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-remote-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-cli-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-remote-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-libs-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-debugsource-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-libs-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-devel-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (noarch) * pacemaker-schemas-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * python3-pacemaker-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-cts-2.1.10+20260618.4bca25e3c1-150700.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 . Critical security update for SUSE's Pacemaker addresses important denial-of-service vulnerability CVE-2026-10649. Act now!. SUSE Linux, Pacemaker, Security Update, Denial of Service, CVE-2026-10649. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.