Issued at: 2026-08-26
Updated at: 2026-08-26
Advisory content derived from Red Hat RHSA-2023:2652, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: pcs security and bug fix update
Description
The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.
Security Fix(es):
* pcs: webpack: Regression of CVE-2023-28154 fixes in the Rocky Linux (CVE-2023-2319)
* rubygem-rack: Denial of service in Multipart MIME parsing (CVE-2023-27530)
* rubygem-rack: denial of service in header parsing (CVE-2023-27539)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* Command 'pcs config checkpoint diff' does not show configuration differences between checkpoints (BZ#2180697)
* Need a way to add a scsi fencing device to a cluster without requiring a restart of all cluster resources (BZ#2180704)
* [WebUI] fence levels prevent loading of cluster status (BZ#2183180)