[Apollo] Advisories Statistics light light Login

RLSA-2026:1241

Security Mirrored from RHSA-2026:1241
Issued at: 2026-02-11
Updated at: 2026-02-11

Synopsis

Important: resource-agents security update



Description

The resource-agents packages provide the Pacemaker and RGManager service managers with a set of scripts. These scripts interface with several services to allow operating in a high-availability (HA) environment.

Security Fix(es):

* urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion (CVE-2025-66418)

* urllib3: urllib3 Streaming API improperly handles highly compressed data (CVE-2025-66471)

* urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) (CVE-2026-21441)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 8 aarch64 Rocky Linux 8 x86_64

Fixes

2419455 2419467 2427726

CVEs

CVE-2025-66418 CVE-2025-66471 CVE-2026-21441

Affected packages

Rocky Linux 8 x86_64 - ResilientStorage

resource-agents-0:4.9.0-54.el8_10.27.src.rpm

Rocky Linux 8 aarch64 - ResilientStorage

resource-agents-0:4.9.0-54.el8_10.27.src.rpm