Red Hat Product Errata RHSA-2026:39323 - Security Advisory Issued: 2026-07-14 Updated: 2026-07-14 RHSA-2026:39323 - Security Advisory Overview Updated Packages Synopsis Important: pacemaker security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for pacemaker is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures. Security Fix(es): pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux High Availability for x86_64 9 x86_64 Red Hat Enterprise Linux High Availability for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux High Availability for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux Resilient Storage for x86_64 9 x86_64 Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux Resilient Storage for IBM z Systems 9 s390x Red Hat Enterprise Linux High Availability for IBM z Systems 9 s390x Red Hat Enterprise Linux Resilient Storage for Power, little endian 9 ppc64le Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux High Availability for Power, little endian 9 ppc64le Red Hat Enterprise Linux High Availability for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux High Availability (for IBM z Systems) - Extended Update Support 9.8 s390x Red Hat Enterprise Linux High Availability (for ARM 64) - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux High Availability for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux High Availability for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - 4 years of updates 9.8 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - 4 years of updates 9.8 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Red Hat Enterprise Linux High Availability for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux High Availability for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux High Availability for IBM z Systems - Extended Life Cycle 9.8 s390x Red Hat Enterprise Linux High Availability for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Life Cycle 9.8 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Life Cycle 9.8 x86_64 Fixes BZ - 2462817 - CVE-2026-10649 pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression CVEs CVE-2026-10649 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM pacemaker-2.1.10-3.el9_8.src.rpm SHA-256: a942213ce2d0b1adc61c8a6b9c29c34a52ea2ab84b66197cc89fc987e66d6de0 x86_64 pacemaker-cli-debuginfo-2.1.10-3.el9_8.i686.rpm SHA-256: d1525dfe967d8597692c370bac745d49edf4b031b518117744b38ce2a3b85b30 pacemaker-cli-debuginfo-2.1.10-3.el9_8.x86_64.rpm SHA-256: 7c867c77b370bb0d60161e7f9e8c7dcca6d8f8376477045194e6d95ccc9a6a03 pacemaker-cluster-libs-2.1.10-3.el9_8.i686.rpm SHA-256: fcca28232bb2a6f7c6fab9734af3154212d11a0780e89bfa5fcbe5da781e7f49 pacemaker-cluster-libs-2.1.10-3.el9_8.x86_64.rpm SHA-256: ee673f37533b56ef6cc1f89a5c17ca269823117a8acb1b5c23161e9debec42a9 pacemaker-cluster-libs-debuginfo-2.1.10-3.el9_8.i686.rpm SHA-256: b99956fc264e3f73cc22114862302751e01fe06eed8934ca0879318306e1c8b3 pacemaker-cluster-libs-debuginfo-2.1.10-3.el9_8.x86_64.rpm SHA-256: c817e4ee41b9db35acbf55fb50daa481e710e740b068cb80ace3c09d8d4abcde pacemaker-debuginfo-2.1.10-3.el9_8.i686.rpm SHA-256: d054811a4af2813b56553b85827fd68964dbd6538c2b63f7c2c4307d0659d13f pacemaker-debuginfo-2.1.10-3.el9_8.x86_64.rpm SHA-256: 71a0e4b05a3248a11346e61a4964c5c848f8984aca4a613dcbd46576ef1bd205 pacemaker-debugsource-2.1.10-3.el9_8.i686.rpm SHA-256: 501b921fdc1e37a313e824181e955628dc0a39cba1a76413ec86befd890d17b8 pacemaker-debugsource-2.1.10-3.el9_8.x86_64.rpm SHA-256: 870d0b0ae23b77eeed6a2b89428cf464552e6bb45addf00237a939c106778c6c pacemaker-libs-2.1.10-3.el9_8.i686.rpm SHA-256: 364d7e5a4d24c5befddef66f2c92c50cb73c1e87338ec417c84d8b026825f0aa pacemaker-libs-2.1.10-3.el9_8.x86_64.rpm SHA-256: 06c80adc410ae5c784eaf43557544ed0e44b7da18901519d26dac075282593b5 pacemaker-libs-debuginfo-2.1.10-3.el9_8.i686.rpm SHA-256: 32d2422f932c57e780448392b5cdf7f21dad9a4a68dfa9e9dbbc07b430fac263 pacemaker-libs-debuginfo-2.1.10-3.el9_8.x86_64.rpm SHA-256: c613c00772ed50f905ad9abd5d28266f62bcd09cfff9f3f4af028ffe8368e984 pacemaker-remote-debuginfo-2.1.10-3.el9_8.i686.rpm SHA-256: 86a21e4ee1b69239ce42039aa5b3c5f140ae10b83ef5ddaa1c6f96b420e09589 pacemaker-remote-debuginfo-2.1.10-3.el9_8.x86_64.rpm SHA-256: 7ce97441216e813a49bc01a6f449ec4453af98e98996ea4473c549615379f6dd pacemaker-schemas-2.1.10-3.el9_8.noarch.rpm SHA-256: 8bbc996b79306e619d44d4e71bb9969dceb5e4c83e2d67a9282d1426ba1f62c3 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM pacemaker-2.1.10-3.el9_8.src.rpm SHA-256: a942213ce2d0b1adc61c8a6b9c29c34a52ea2ab84b66197cc89fc987e66d6de0 x86_64 pacemaker-cli-debuginfo-2.1.10-3.el9_8.i686.rpm SHA-256: d1525dfe967d8597692c370bac745d49edf4b031b518117744b38ce2a3b85b30 pacemaker-cli-debuginfo-2.1.10-3.el9_8.x86_64.rpm SHA-256: 7c867c77b370bb0d60161e7f9e8c7dcca6d8f8376477045194e6d95ccc9a6a03 pacemaker-cluster-libs-2.1.10-3.el9_8.i686.rpm SHA-256: fcca28232bb2a6f7c6fab9734af3154212d11a0780e89bfa5fcbe5da781e7f49 pacemaker-cluster-libs-2.1.10-3.el9_8.x86_64.rpm SHA-256: ee673f37533b56ef6cc1f89a5c17ca269823117a8acb1b5c23161e9debec42a9 pacemaker-cluster-libs-debuginfo-2.1.10-3.el9_8.i686.rpm SHA-256: b99956fc264e3f73cc22114862302751e01fe06eed8934ca0879318306e1c8b3 pacemaker-cluster-libs-debuginfo-2.1.10-3.el9_8.x86_64.rpm SHA-256: c817e4ee41b9db35acbf55fb50daa481e710e740b068cb80ace3c09d8d4abcde pacemaker-debuginfo-2.1.10-3.el9_8.i686.rpm SHA-256: d054811a4af2813b56553b85827fd68964dbd6538c2b63f7c2c4307d0659d13f pacemaker-debuginfo-2.1.10-3.el9_8.x86_64.rpm SHA-256: 71a0e4b05a3248a11346e61a4964c5c848f8984aca4a613dcbd46576ef1bd205 pacemaker-debugsource-2.1.10-3.el9_8.i686.rpm SHA-256: 501b921fdc1e37a313e824181e955628dc0a39cba1a76413ec86befd890d17b8 pacemaker-debugsource-2.1.10-3.el9_8.x86_64.rpm SHA-256: 870d0b0ae23b77eeed6a2b89428cf464552e6bb45addf00237a939c106778c6c pacemaker-libs-2.1.10-3.el9_8.i686.rpm SHA-256: 364d7e5a4d24c5befddef66f2c92c50cb73c1e87338ec417c84d8b026825f0aa pacemaker-libs-2.1.10-3.el9_8.x86_64.rpm SHA-256: 06c80adc410ae5c784eaf43557544ed0e44b7da18901519d26dac075282593b5 pacemaker-libs-debuginfo-2.1.10-3.el9_8.i686.rpm SHA-256: 32d2422f932c57e780448392b5cdf7f21dad9a4a68dfa9e9dbbc07b430fac263 pacemaker-libs-debuginfo-2.1.10-3.el9_8.x86_64.rpm SHA-256: c613c00772ed50f905ad9abd5d28266f62bcd09cfff9f3f4af028ffe8368e984 pacemaker-remote-debuginfo-2.1.10-3.el9_8.i686.rpm SHA-256: 86a21e4ee1b69239ce42039aa5b3c5f140ae10b83ef5ddaa1c6f96b420e09589 pacemaker-remote-debuginfo-2.1.10-3.el9_8.x86_64.rpm SHA-256: 7ce97441216e813a49bc01a6f449ec4453af98e98996ea4473c549615379f6dd pacemaker-schemas-2.1.10-3.el9_8.noarch.rpm SHA-256: 8bbc996b79306e619d44d4e71bb9969dceb5e4c83e2d67a9282d1426ba1f62c3 Red Hat Enterprise Linux for IBM z Systems 9 SRPM pacemaker-2.1.10-3.el9_8.src.rpm SHA-256: a942213ce2d0b1adc61c8a6b9c29c34a52ea2ab84b66197cc89fc987e66d6de0 s390x pac
An integer overflow vulnerability (CVE-2026-10649, CVSS 8.6 HIGH) in the Pacemaker cluster resource manager allows for remote denial of service via crafted message decompression. This security update, rated Important by Red Hat, affects Pacemaker packages for Red Hat Enterprise Linux 9. The fix is included in the packages provided in Red Hat advisory RHSA-2026:39323, and administrators should apply the update following the referenced Red Hat solution article.