Red Hat Product Errata RHSA-2026:41042 - Security Advisory Issued: 2026-07-16 Updated: 2026-07-16 RHSA-2026:41042 - Security Advisory Overview Updated Packages Synopsis Important: pacemaker security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for pacemaker is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Pacemaker cluster resource manager is a collection of technologies working together to maintain data integrity and application availability in the event of failures. Security Fix(es): pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression (CVE-2026-10649) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux High Availability for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux High Availability for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux High Availability (for IBM z Systems) - Extended Update Support 9.6 s390x Red Hat Enterprise Linux High Availability (for ARM 64) - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux High Availability for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux High Availability for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - 4 years of updates 9.6 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - 4 years of updates 9.6 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Red Hat Enterprise Linux High Availability for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux High Availability for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux High Availability for IBM z Systems - Extended Life Cycle 9.6 s390x Red Hat Enterprise Linux High Availability for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Life Cycle 9.6 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Life Cycle 9.6 x86_64 Fixes BZ - 2462817 - CVE-2026-10649 pacemaker: Pacemaker: Denial of Service via integer overflow in remote message decompression CVEs CVE-2026-10649 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM pacemaker-2.1.9-1.4.el9_6.src.rpm SHA-256: a5942760756529ba383e91f62e5d47d2560b95fa4f22e63b6d7d6bec72eede4f x86_64 pacemaker-cli-debuginfo-2.1.9-1.4.el9_6.i686.rpm SHA-256: 41401fa70dcc96d246b0bc7d39aec1743ded7b6acdb0c836f467175e0953d1a8 pacemaker-cli-debuginfo-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: 1297a4a14774d0c5d12d95370397e18b93392f0bafaca42bd6504ea79563fef9 pacemaker-cluster-libs-2.1.9-1.4.el9_6.i686.rpm SHA-256: b230f53d7053e0580c67b91932999e499adefcf1db058b509dbaf0240df5f4ca pacemaker-cluster-libs-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: c2f3052926d86e9a95c0aa4b759dc2d2ca5b76c23d00be55803a5793290eb675 pacemaker-cluster-libs-debuginfo-2.1.9-1.4.el9_6.i686.rpm SHA-256: 49dadaa8564168ca31f7ea16d71220f2fca9a0adce26dc34c187997dfb4fa83e pacemaker-cluster-libs-debuginfo-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: 4f075da130e598c674e41dfd14b0b1c10c08d7a0569bf29144dc032e4b594264 pacemaker-debuginfo-2.1.9-1.4.el9_6.i686.rpm SHA-256: 8ca1a80bccdaf5bb7b55d3b2c0748ed94295cb21745453f89078db3c0aaa2943 pacemaker-debuginfo-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: 4c782490105d9fe2423b53ee7d9ea1f671510a4237428aef6c9c4367ea2cbe42 pacemaker-debugsource-2.1.9-1.4.el9_6.i686.rpm SHA-256: 0382703b5d954ffb39677ded4cf89e624ea72ba609fb90d50e75ca9e08a6e19d pacemaker-debugsource-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: 6571786c5dc284b82d3ff518575aa3d9fd2ed278b04e8170cabb574758ac7224 pacemaker-libs-2.1.9-1.4.el9_6.i686.rpm SHA-256: 6945f44ff52d73a1d65afc0714dab25de924665108c557d08ee0cb81f788630b pacemaker-libs-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: b72069523b573c14fade1c1bd47d0aee5a59d60c290043555f1826b08e774f68 pacemaker-libs-debuginfo-2.1.9-1.4.el9_6.i686.rpm SHA-256: b51afa7b21e7dedfe215d899311c6b49d9ad29dc82a0156b7514f81777b00222 pacemaker-libs-debuginfo-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: a5a1c4a000fcb85be927002323142397077a52368ae4e4ca96e373c64c98bb16 pacemaker-remote-debuginfo-2.1.9-1.4.el9_6.i686.rpm SHA-256: 57a53794c29158040987049b9f76e0c0041aea8bd70354d1bf488037df6bebbd pacemaker-remote-debuginfo-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: b3fde83b629fd489eb190c97080cefb1101478e847ef9a4de81fb584f5e19653 pacemaker-schemas-2.1.9-1.4.el9_6.noarch.rpm SHA-256: 51098924a81dd446dc29e9bcae45749653943afae64c9a625d27ee0acdcddf99 Red Hat Enterprise Linux Server - AUS 9.6 SRPM pacemaker-2.1.9-1.4.el9_6.src.rpm SHA-256: a5942760756529ba383e91f62e5d47d2560b95fa4f22e63b6d7d6bec72eede4f x86_64 pacemaker-cli-debuginfo-2.1.9-1.4.el9_6.i686.rpm SHA-256: 41401fa70dcc96d246b0bc7d39aec1743ded7b6acdb0c836f467175e0953d1a8 pacemaker-cli-debuginfo-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: 1297a4a14774d0c5d12d95370397e18b93392f0bafaca42bd6504ea79563fef9 pacemaker-cluster-libs-2.1.9-1.4.el9_6.i686.rpm SHA-256: b230f53d7053e0580c67b91932999e499adefcf1db058b509dbaf0240df5f4ca pacemaker-cluster-libs-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: c2f3052926d86e9a95c0aa4b759dc2d2ca5b76c23d00be55803a5793290eb675 pacemaker-cluster-libs-debuginfo-2.1.9-1.4.el9_6.i686.rpm SHA-256: 49dadaa8564168ca31f7ea16d71220f2fca9a0adce26dc34c187997dfb4fa83e pacemaker-cluster-libs-debuginfo-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: 4f075da130e598c674e41dfd14b0b1c10c08d7a0569bf29144dc032e4b594264 pacemaker-debuginfo-2.1.9-1.4.el9_6.i686.rpm SHA-256: 8ca1a80bccdaf5bb7b55d3b2c0748ed94295cb21745453f89078db3c0aaa2943 pacemaker-debuginfo-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: 4c782490105d9fe2423b53ee7d9ea1f671510a4237428aef6c9c4367ea2cbe42 pacemaker-debugsource-2.1.9-1.4.el9_6.i686.rpm SHA-256: 0382703b5d954ffb39677ded4cf89e624ea72ba609fb90d50e75ca9e08a6e19d pacemaker-debugsource-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: 6571786c5dc284b82d3ff518575aa3d9fd2ed278b04e8170cabb574758ac7224 pacemaker-libs-2.1.9-1.4.el9_6.i686.rpm SHA-256: 6945f44ff52d73a1d65afc0714dab25de924665108c557d08ee0cb81f788630b pacemaker-libs-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: b72069523b573c14fade1c1bd47d0aee5a59d60c290043555f1826b08e774f68 pacemaker-libs-debuginfo-2.1.9-1.4.el9_6.i686.rpm SHA-256: b51afa7b21e7dedfe215d899311c6b49d9ad29dc82a0156b7514f81777b00222 pacemaker-libs-debuginfo-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: a5a1c4a000fcb85be927002323142397077a52368ae4e4ca96e373c64c98bb16 pacemaker-remote-debuginfo-2.1.9-1.4.el9_6.i686.rpm SHA-256: 57a53794c29158040987049b9f76e0c0041aea8bd70354d1bf488037df6bebbd pacemaker-remote-debuginfo-2.1.9-1.4.el9_6.x86_64.rpm SHA-256: b3fde83b629fd489eb190c97080cefb1101478e847ef9a4de81fb584f5e19653 pacemaker-schemas-2.1.9-1.4.el9_6.noarch.rpm SHA-256: 51098924a81dd446dc29e9bcae45749653943afae64c9a625d27ee0acdcddf99 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM pacemaker-2.1.9-1.4.el9_6.src.rpm SHA-256: a5942760756529ba383e91f62e5d47d2560b95fa4f22e63b6d7d6bec72eede4f s390x pacemaker-cli-debuginfo-2.1.9-1.4.el9_6.s390x.rpm SHA-256: a0fd996a95d1e46f0b2d1ead343dba75d3bc7f252d23748edcace0324bf33a32 pacemaker-cluster-libs-2.1.9-1.4.el9_6.s390x.rpm SHA-256: ce846c6ebb7795ec06c845b6b0e85da36d0059289076879db1423312695129b0 pacemaker-cluster-libs-debuginfo-2.1.9-1.4.el9_6.s390x.rpm SHA-256: b95e8a13a5c32f6bd1420dee263224aff60399dadea05e4f2c371b232521d34e pacemaker-debuginfo-2.1.9-1.4.el9_6.s390x.rpm SHA-256: 4f66c6d65a0b67f96a230b058c87cd66492f004550660b9367269d82cb048f0f pacemaker-debugsource-2.1.9-1.4.el9_6.s390x.r
A critical integer overflow vulnerability (CVE-2026-10649, CVSS 8.6 HIGH) in the Pacemaker cluster resource manager allows remote attackers to cause a denial of service via crafted message decompression. The vulnerability affects Pacemaker packages for Red Hat Enterprise Linux 9.6 Extended Update Support and related variants. Red Hat has released a security update rated as Important to address this issue.