[ClusterLabs Developers] Pacemaker security patches for 2.0.3 / 2.0.4 code bases

Ken Gaillot kgaillot at redhat.com
Tue Oct 27 15:09:12 UTC 2020


Hi all,

As announced on the users at clusterlabs.org list, an ACL bypass
vulnerability was found in Pacemaker. The 1.1, 2.0, and master branches
will all have fixes merged today.

In case anyone is building the 2.0.3 or 2.0.4 releases, I've attached
patches here for those points in the code base.
-- 
Ken Gaillot <kgaillot at redhat.com>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: CVE-2020-25654_2.0.3.patch
Type: text/x-patch
Size: 19203 bytes
Desc: not available
URL: <http://lists.clusterlabs.org/pipermail/developers/attachments/20201027/9ac0fa57/attachment-0002.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: CVE-2020-25654_2.0.4.patch
Type: text/x-patch
Size: 19168 bytes
Desc: not available
URL: <http://lists.clusterlabs.org/pipermail/developers/attachments/20201027/9ac0fa57/attachment-0003.bin>


More information about the Developers mailing list