[ClusterLabs] PCS hotfix releases for CVE-2026-84828
Michal Pospíšil
mpospisi at redhat.com
Thu Sep 10 12:34:01 UTC 2026
I would like to announce hotfix releases of PCS, versions:
- 0.12.3.1,
- 0.11.12.2,
- 0.10.20.
Source code is available at:
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.12.3.1.tar.gz
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.11.12.2.tar.gz
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.10.20.tar.gz
or
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.12.3.1.zip
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.11.12.2.zip
https://github.com/ClusterLabs/pcs/archive/refs/tags/v0.10.20.zip
These releases fix a security vulnerability in the `pcs host auth`
command, which could previously be exploited by non-root users to
read arbitrary files on the filesystem.
The vulnerability was discovered by Peter Romančík and it was filed
as CVE-2026-84828 [1] with a CVSSv3.1 score of 6.5.
Stay safe and update,
Michal
[1] https://www.cve.org/CVERecord?id=CVE-2026-84828
More information about the Users
mailing list