Red Hat Product Errata RHSA-2026:22131 - Security Advisory Issued: 2026-06-01 Updated: 2026-06-01 RHSA-2026:22131 - Security Advisory Overview Updated Packages Synopsis Important: resource-agents security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for resource-agents is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The resource-agents packages provide the Pacemaker and RGManager service managers with a set of scripts. These scripts interface with several services to allow operating in a high-availability (HA) environment. Security Fix(es): pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Red Hat Enterprise Linux High Availability for x86_64 - Telecommunications Update Service 8.8 x86_64 Red Hat Enterprise Linux High Availability for x86_64 - Extended Update Support Extension 8.8 x86_64 Fixes BZ - 2448553 - CVE-2026-30922 pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion CVEs CVE-2026-30922 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 8.8 SRPM resource-agents-4.9.0-40.el8_8.19.src.rpm SHA-256: 5049722dfb74503f07d36dfeefe3e686a62473a099872a49ed6d2d32a53ccd68 ppc64le resource-agents-4.9.0-40.el8_8.19.ppc64le.rpm SHA-256: d1283f06c09139f30ec65527e003399b18b7f089c63948056123fb2a9116ba33 resource-agents-debuginfo-4.9.0-40.el8_8.19.ppc64le.rpm SHA-256: d1a42a3f908ed1f624c22c2dd0372b8c3a3c3a290657bb84e096c8bcb5d3870a resource-agents-debugsource-4.9.0-40.el8_8.19.ppc64le.rpm SHA-256: a54654cfe02a50210fda223f728a5940f858680e701f646d7d7d5a6230a28572 resource-agents-paf-4.9.0-40.el8_8.19.ppc64le.rpm SHA-256: 9f5d22e21a3dd86a86eb3a78e9efeac52b1b3effe3432f8fea545f20035ce2c9 Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions 8.8 SRPM resource-agents-4.9.0-40.el8_8.19.src.rpm SHA-256: 5049722dfb74503f07d36dfeefe3e686a62473a099872a49ed6d2d32a53ccd68 x86_64 resource-agents-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 90958d9379c99d7b2ad52558cbdbfdde309de49d27e22801f58b435f24211181 resource-agents-aliyun-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: a5562ee102c5a4c1695f81e3e538b5213502af53c06e826dc8a050757b602d99 resource-agents-aliyun-debuginfo-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 2d2c30e03b0834938479239bfd03178590fea7b065ad048b856e1fb31b224778 resource-agents-debuginfo-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: fd72aa6f9e9fdf1c5d9906bb78726618f237076f097482a1805ce21d39db95a8 resource-agents-debugsource-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 00223eb10a72232c1ecf250ec456aa2e49c0d88da7809a40320b540036069263 resource-agents-gcp-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 5963c9fe12085e43b02b5bd0296f6537e79974e3603767955238543d6a9e4191 resource-agents-paf-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 1fd7b3697b574a0add9e4cb2db4b8c1d5044f6ed55e35268c0085b6040c497c9 Red Hat Enterprise Linux High Availability for x86_64 - Telecommunications Update Service 8.8 SRPM resource-agents-4.9.0-40.el8_8.19.src.rpm SHA-256: 5049722dfb74503f07d36dfeefe3e686a62473a099872a49ed6d2d32a53ccd68 x86_64 resource-agents-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 90958d9379c99d7b2ad52558cbdbfdde309de49d27e22801f58b435f24211181 resource-agents-aliyun-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: a5562ee102c5a4c1695f81e3e538b5213502af53c06e826dc8a050757b602d99 resource-agents-aliyun-debuginfo-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 2d2c30e03b0834938479239bfd03178590fea7b065ad048b856e1fb31b224778 resource-agents-debuginfo-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: fd72aa6f9e9fdf1c5d9906bb78726618f237076f097482a1805ce21d39db95a8 resource-agents-debugsource-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 00223eb10a72232c1ecf250ec456aa2e49c0d88da7809a40320b540036069263 resource-agents-gcp-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 5963c9fe12085e43b02b5bd0296f6537e79974e3603767955238543d6a9e4191 resource-agents-paf-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 1fd7b3697b574a0add9e4cb2db4b8c1d5044f6ed55e35268c0085b6040c497c9 Red Hat Enterprise Linux High Availability for x86_64 - Extended Update Support Extension 8.8 SRPM resource-agents-4.9.0-40.el8_8.19.src.rpm SHA-256: 5049722dfb74503f07d36dfeefe3e686a62473a099872a49ed6d2d32a53ccd68 x86_64 resource-agents-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 90958d9379c99d7b2ad52558cbdbfdde309de49d27e22801f58b435f24211181 resource-agents-aliyun-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: a5562ee102c5a4c1695f81e3e538b5213502af53c06e826dc8a050757b602d99 resource-agents-aliyun-debuginfo-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 2d2c30e03b0834938479239bfd03178590fea7b065ad048b856e1fb31b224778 resource-agents-debuginfo-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: fd72aa6f9e9fdf1c5d9906bb78726618f237076f097482a1805ce21d39db95a8 resource-agents-debugsource-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 00223eb10a72232c1ecf250ec456aa2e49c0d88da7809a40320b540036069263 resource-agents-gcp-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 5963c9fe12085e43b02b5bd0296f6537e79974e3603767955238543d6a9e4191 resource-agents-paf-4.9.0-40.el8_8.19.x86_64.rpm SHA-256: 1fd7b3697b574a0add9e4cb2db4b8c1d5044f6ed55e35268c0085b6040c497c9 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This update addresses CVE-2026-30922 (CVSS 7.5 HIGH), a denial-of-service vulnerability in the `pyasn1` library used by the resource-agents package, caused by unbounded recursion. The vulnerability affects `pyasn1` versions prior to 0.6.3, and the provided Red Hat packages contain the fix.