INFSA-2025:11047: pcs security update

Information about definition

Identificator: INFSA-2025:11047

Type: security

Release date: 2025-07-17 21:50:18 UTC

Information about package

The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.

Vulnerabilities description

  • CVE-2024-49761

    A flaw was found in the REXML XML toolkit for Ruby. Parsing XML data containing a large number of digits between &# and x...; in a hex numeric character reference (&#x...;) can trigger a regular expression denial of service (ReDoS) condition, leading to a denial of service.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 7.5 no information
Critical, important, moderate, low

Updated packages