INFSA-2024:3659: Booth security update

Information about definition

Identificator: INFSA-2024:3659

Type: security

Release date: 2024-08-27 10:04:59 UTC

Information about package

The Booth cluster ticket manager is a component to bridge high availability clusters spanning multiple sites, in particular, to provide decision inputs to local Pacemaker cluster resource managers. It operates as a distributed consensus-based service, presumably on a separate physical network. Tickets facilitated by a Booth formation are the units of authorization that can be bound to certain resources. This will ensure that the resources are run at only one (granted) site at a time.

Vulnerabilities description

  • CVE-2024-3049

    A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
NIST — CVE-2024-3049
no information 5.9 no information
Critical, important, moderate, low

Updated packages