[Apollo] Advisories Red Hat Advisories Statistics light light Login

RHSA-2023:6316

Security
Issued at: 2023-11-07
launch
Open original
Override

Synopsis

Low: pcs security, bug fix, and enhancement update



Description

The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.

Security Fix(es):

* decode-uri-component: improper input validation resulting in DoS (CVE-2022-38900)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.3 Release Notes linked from the References section.



Affected products

Red Hat Enterprise Linux for ARM 64 - 9 Red Hat Enterprise Linux for IBM z Systems - 9 Red Hat Enterprise Linux for Power, little endian - 9 Red Hat Enterprise Linux for x86_64 - 9

Fixes

2170644

CVEs

CVE-2022-38900

Affected packages

pcs-0:0.11.6-3.el9.aarch64 pcs-0:0.11.6-3.el9.ppc64le pcs-0:0.11.6-3.el9.s390x pcs-0:0.11.6-3.el9.src pcs-0:0.11.6-3.el9.x86_64 pcs-snmp-0:0.11.6-3.el9.aarch64 pcs-snmp-0:0.11.6-3.el9.ppc64le pcs-snmp-0:0.11.6-3.el9.s390x pcs-snmp-0:0.11.6-3.el9.x86_64