Red Hat Product Errata RHSA-2026:40833 - Security Advisory Issued: 2026-07-16 Updated: 2026-07-16 RHSA-2026:40833 - Security Advisory Overview Updated Packages Synopsis Important: pacemaker security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for pacemaker is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures. Security Fix(es): pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux High Availability for x86_64 10 x86_64 Red Hat Enterprise Linux High Availability for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux High Availability for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux High Availability for IBM z Systems 10 s390x Red Hat Enterprise Linux High Availability for Power, little endian 10 ppc64le Red Hat Enterprise Linux High Availability for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux High Availability (for IBM z Systems) - Extended Update Support 10.2 s390x Red Hat Enterprise Linux High Availability (for ARM 64) - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux High Availability for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux High Availability for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux High Availability for Power, little endian - 4 years of updates 10.2 ppc64le Red Hat Enterprise Linux High Availability for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Red Hat Enterprise Linux High Availability for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux High Availability for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux High Availability for IBM z Systems - Extended Life Cycle 10.2 s390x Red Hat Enterprise Linux High Availability for x86_64 - Extended Life Cycle 10.2 x86_64 Fixes BZ - 2462817 - CVE-2026-10649 pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression CVEs CVE-2026-10649 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM pacemaker-3.0.1-5.el10_2.1.src.rpm SHA-256: 0d80944d2873d3bac58982d1c825d640ce1a71144ca1af2b3e7b91cf1268752c x86_64 pacemaker-cli-debuginfo-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: 5dd3b7f0736c5a2d9156c9dbef7a31c2b32c93de3beec8a936b88b14def27821 pacemaker-cluster-libs-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: 230fd7a11e3a29811e0573cb7dfc4cb8ffc31d50f14b01dd9e9a0c5cd1687e50 pacemaker-cluster-libs-debuginfo-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: 5031f4cebf0aa34c8caa922512b9f4d0e1cf3782a34436f4d10c7ffa76515606 pacemaker-debuginfo-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: e4f7a2be94eb864db8b13ddc4d86d7b01b6f21982f3c4b0429c5679d54f24199 pacemaker-debugsource-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: 086a8b21276fba4a15ba4c14374aa31460a1047dddaf7cb7d124bab3d9b4ffa3 pacemaker-libs-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: 65a6e8f38e03a43dcd4956a410cbdb08cc10b1502553acd9b0f9c72db5ebead7 pacemaker-libs-debuginfo-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: f0d9866a8a0101e74876c9e9dee587a8f75ae893634d3a6469e23dd5c1401376 pacemaker-remote-debuginfo-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: d815e5b395095ab06dfb93bda36735164e12b3e7a161cd99b0e3fea8bbf709f4 pacemaker-schemas-3.0.1-5.el10_2.1.noarch.rpm SHA-256: a7556e4fd738cb584ea0b32e7f5f70db4cb78728c7583b8f07032be08babfd05 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM pacemaker-3.0.1-5.el10_2.1.src.rpm SHA-256: 0d80944d2873d3bac58982d1c825d640ce1a71144ca1af2b3e7b91cf1268752c x86_64 pacemaker-cli-debuginfo-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: 5dd3b7f0736c5a2d9156c9dbef7a31c2b32c93de3beec8a936b88b14def27821 pacemaker-cluster-libs-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: 230fd7a11e3a29811e0573cb7dfc4cb8ffc31d50f14b01dd9e9a0c5cd1687e50 pacemaker-cluster-libs-debuginfo-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: 5031f4cebf0aa34c8caa922512b9f4d0e1cf3782a34436f4d10c7ffa76515606 pacemaker-debuginfo-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: e4f7a2be94eb864db8b13ddc4d86d7b01b6f21982f3c4b0429c5679d54f24199 pacemaker-debugsource-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: 086a8b21276fba4a15ba4c14374aa31460a1047dddaf7cb7d124bab3d9b4ffa3 pacemaker-libs-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: 65a6e8f38e03a43dcd4956a410cbdb08cc10b1502553acd9b0f9c72db5ebead7 pacemaker-libs-debuginfo-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: f0d9866a8a0101e74876c9e9dee587a8f75ae893634d3a6469e23dd5c1401376 pacemaker-remote-debuginfo-3.0.1-5.el10_2.1.x86_64.rpm SHA-256: d815e5b395095ab06dfb93bda36735164e12b3e7a161cd99b0e3fea8bbf709f4 pacemaker-schemas-3.0.1-5.el10_2.1.noarch.rpm SHA-256: a7556e4fd738cb584ea0b32e7f5f70db4cb78728c7583b8f07032be08babfd05 Red Hat Enterprise Linux for IBM z Systems 10 SRPM pacemaker-3.0.1-5.el10_2.1.src.rpm SHA-256: 0d80944d2873d3bac58982d1c825d640ce1a71144ca1af2b3e7b91cf1268752c s390x pacemaker-cli-debuginfo-3.0.1-5.el10_2.1.s390x.rpm SHA-256: 79c8bcf13aefdc8a550e7503efe038ed350edb723d5288031afba71ce4ca1eb8 pacemaker-cluster-libs-3.0.1-5.el10_2.1.s390x.rpm SHA-256: f0bdc5cdc2276145247146993ba96999ef346f578e0a0e1cca2c429d8bd9df4b pacemaker-cluster-libs-debuginfo-3.0.1-5.el10_2.1.s390x.rpm SHA-256: 98b172c77af8e4f5ed68a11a47d8d10274797f7049c6e226e13a8ce003ba6c18 pacemaker-debuginfo-3.0.1-5.el10_2.1.s390x.rpm SHA-256: 844d9b937878610d1277fef22cfd1a0c106e116c317c2313db3519f225c0fc1e pacemaker-debugsource-3.0.1-5.el10_2.1.s390x.rpm SHA-256: 33d71768091f512c5902d4860e5caa52c8b398530d8452ec9e7599608b3bcd7b pacemaker-libs-3.0.1-5.el10_2.1.s390x.rpm SHA-256: b2bc7291c49d65b19bbb92ebf405292b175c63a8b33b529a7e182bb0dccffed3 pacemaker-libs-debuginfo-3.0.1-5.el10_2.1.s390x.rpm SHA-256: 09c22d76a93b32b62e043a94e3a3bc1ed4f1104df8762e53f5a9d8ea828885f7 pacemaker-remote-debuginfo-3.0.1-5.el10_2.1.s390x.rpm SHA-256: aa62fb634ae96c79cbb8113c288c2b0264b7075b82e506032086a37cb2787b16 pacemaker-schemas-3.0.1-5.el10_2.1.noarch.rpm SHA-256: a7556e4fd738cb584ea0b32e7f5f70db4cb78728c7583b8f07032be08babfd05 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM pacemaker-3.0.1-5.el10_2.1.src.rpm SHA-256: 0d80944d2873d3bac58982d1c825d640ce1a71144ca1af2b3e7b91cf1268752c s390x pacemaker-cli-debuginfo-3.0.1-5.el10_2.1.s390x.rpm SHA-256: 79c8bcf13aefdc8a550e7503efe038ed350edb723d5288031afba71ce4ca1eb8 pacemaker-cluster-libs-3.0.1-5.el10_2.1.s390x.rpm SHA-256: f0bdc5cdc2276145247146993ba96999ef346f578e0a0e1cca2c429d8bd9df4b pacemaker-cluster-libs-debuginfo-3.0.1-5.el10_2.1.s390x.rpm SHA-256: 98b172c77af8e4f5ed68a11a47d8d10274797f7049c6e226e13a8ce003ba6c18 pacemaker-debuginfo-3.0.1-5.el10_2.1.s390x.rpm SHA-256: 844d9b937878610d1277fef22cfd1a0c106e116c317c2313db3519f225c0fc1e pacemaker-debugsource-3.0.1-5.el10_2.1.s390x.rpm SHA-256: 33d71768091f512c5902d4860e5caa52c8b398530d8452ec9e7599608b3bcd7b pacemaker-libs-3.0.1-5.el10_2.1.s390x.rpm SHA-256: b2bc7291c49d65b19bbb92ebf405292b175c63a8b33b529a7e182bb0dccffed3 pacemaker-libs-debuginfo-3.0.1-5.el10_2.1.s390x.rpm SHA-256: 09c22d76a93b32b62e043a94e3a3bc1ed4f1104df8762e53f5a9d8ea828885f7 pacemaker-remote-debuginfo-3.0.1-5.el10_2.1.s390x.rpm SHA-256: aa62fb634ae96c79cbb8113c288c2b0264b7075b82e506032086a37cb2787b16 pacemaker-schemas-3.0.1-5.el10_2.1.noarch.rpm SHA-256: a7556e4fd738cb584ea0b32e7f5f70db4cb78728c7583b8f07032be08babfd05 Red Hat Enterprise Linux for Power, little endian 10 SRPM pacemaker-3.0.1-5.el10_2.1.src.rpm SHA-256: 0d80944d2873d3bac58982d1c825d640ce1a71144ca1af2b3e7b91cf1268752c ppc64le pacemaker-cli-debuginfo-3.0.1-5.el10_2.1.ppc64le.rpm SHA-256: 2c84f11039c795de11ca10afb722717109512c30b38a83bd7c1721fec28b8163 pacemaker-cluster-libs-3.0.1-5.el10_2.1.ppc64le.rpm SHA-256: dd31dcd428d0cfa98912596cce011c1f93ccc78dedadb56bf21770423ed516bb pacemaker-cluster-libs-debuginfo-3.0.1-5.el10_2.1.ppc64le.rpm SHA-256: 38cac7ca3e44e9813ae2f997e79302779e150e0a9a86fd2fd651
An integer overflow vulnerability (CVE-2026-10649, CVSS 8.6 HIGH) in the Pacemaker cluster resource manager allows remote attackers to cause a denial of service via crafted message decompression. The security update addresses this flaw for Red Hat Enterprise Linux 10 and its High Availability variants; specific affected and fixed version numbers are not provided in the advisory. IT professionals managing Pacemaker clusters should apply the referenced Red Hat update immediately to mitigate this risk.