Red Hat Product Errata RHSA-2026:50653 - Security Advisory Issued: 2026-08-05 Updated: 2026-08-05 RHSA-2026:50653 - Security Advisory Overview Updated Packages Synopsis Important: fence-agents security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for fence-agents is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): httplib2: httplib2: Denial of Service via unbounded decompression of HTTP response bodies (CVE-2026-59939) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux High Availability for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux High Availability for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - 4 years of updates 9.2 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - 4 years of updates 9.2 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux High Availability for x86_64 - Advanced Update Support 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Red Hat Enterprise Linux High Availability for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux High Availability for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux High Availability for IBM z Systems - Extended Life Cycle 9.2 s390x Red Hat Enterprise Linux High Availability for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Life Cycle 9.2 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Life Cycle 9.2 x86_64 Fixes BZ - 2498212 - CVE-2026-59939 httplib2: httplib2: Denial of Service via unbounded decompression of HTTP response bodies CVEs CVE-2026-59939 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM fence-agents-4.10.0-43.el9_2.24.src.rpm SHA-256: 9f9376aa050bcda97fcc2a22af3cb28842b62ed459c593326b75e32f7323408a x86_64 fence-agents-common-4.10.0-43.el9_2.24.noarch.rpm SHA-256: 00bfb7778b806fb8376de257cdccc4f0fa2211cc51a9a3088f299c92ac134a74 fence-agents-compute-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 11b353029fb8ce3c45b9436098d4d5b8a95c18496db9096272db63ba00050f47 fence-agents-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 5d30b659474099e76fe44fcd87a599f7c5c6a9c466ec57df1c1418f423d094ae fence-agents-debugsource-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 779faf78154f4c45fc564ed2ce0c5129ac12013c2daf7447181554365a213803 fence-agents-ibm-powervs-4.10.0-43.el9_2.24.noarch.rpm SHA-256: f429232ef915f8d0be74155c7a9031caf1b235a9a3b167d781fc98c4f281040a fence-agents-ibm-vpc-4.10.0-43.el9_2.24.noarch.rpm SHA-256: 867109528b014fa079351d5cee2920b91111af9c20fb04beaf17c4eff1bcea5d fence-agents-kdump-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 49b7a291486213c6f10bb9367e2b2c554127898ce8e77c797e5241a0b609760e fence-agents-kubevirt-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: d5bf9b67cd145bffdb838e33d44c43c36ae8f48e24d376f96dccaa2a5e000d48 fence-agents-kubevirt-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 50a5e2dde1a67c747b706dd69486ecee3f9cb31d371ac16be21ed479997493a7 fence-agents-virsh-4.10.0-43.el9_2.24.noarch.rpm SHA-256: f7f96e1d076d985b6c64e407dd214a13a04c8582ce8b03e928f703d4eff72bbf fence-virt-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: d417dd9468c22129deb22a82cf120fe546dfc239bf9723bbd87b30f9912e6b5c fence-virt-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 58a6d86a93c5e79fc1300d6164761ddf23bad4f8c3504513b58ee747897bb9b1 fence-virtd-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 9adad3029f101c8f31d4a297a68cabe3296586f49b58a45f1a5d3c68108873b1 fence-virtd-cpg-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: c61e32426e07456eed567a2e9c0b8d3b845c74cffead20863cb1e3e330027257 fence-virtd-cpg-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 9b78ac1fe3d8ca9279d85cedd32cbb391c25179285aa6a25a0a5f9bd5ff429a6 fence-virtd-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: ce5b0af2b5e04013d4b560d9c3caf70df93b760f0f8968ac6af6ac00a7e07b66 fence-virtd-libvirt-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 5e5029bfda09fa72d66c0933c0d7561461a8a2ad2f2745af436b1a003c047a17 fence-virtd-libvirt-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 75f9f9264f3375c27f1b99477edbd080df4275b9c29fa4ff2195b8fa31bd66a5 fence-virtd-multicast-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 1935a7b47cfaaf96762d93253beaa0205ccacf34da767b81a53e141875bb3637 fence-virtd-multicast-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 24b02ad1694412935b262185b44fbeebfa7846152494208e428c4d2a8d59dfdb fence-virtd-serial-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: d2440d1d7e6674d77d32920a2c0674b2834aeb8f262f6a8d8d5ba9a48b725875 fence-virtd-serial-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 599c0c0cf69d6dec2079a7d0ce9d71c274dcb09798767eece53a9ff6c4287b11 fence-virtd-tcp-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 3eb11dac2dd385be34f5bde8cb6f38f67137d376f5e2b06d987ec384b25ad0cd fence-virtd-tcp-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: b07765e7a6bd924e87bb5380336a739af50be41b4d18add944d564333a8f955a ha-cloud-support-debuginfo-4.10.0-43.el9_2.24.x86_64.rpm SHA-256: 7a09ea37e76cf372218c38c97f6b59add42a1057916720c1bbfa4a8a59896829 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM fence-agents-4.10.0-43.el9_2.24.src.rpm SHA-256: 9f9376aa050bcda97fcc2a22af3cb28842b62ed459c593326b75e32f7323408a ppc64le fence-agents-common-4.10.0-43.el9_2.24.noarch.rpm SHA-256: 00bfb7778b806fb8376de257cdccc4f0fa2211cc51a9a3088f299c92ac134a74 fence-agents-compute-4.10.0-43.el9_2.24.ppc64le.rpm SHA-256: 9f4c27d8acbe02935d3dd0952fedf1ca0de338305e3985da4e1042ae98b60b24 fence-agents-debuginfo-4.10.0-43.el9_2.24.ppc64le.rpm SHA-256: 98a553c3b04b148edcaa3fbd61623393df51f85bdcade437f2c08d94c411ab3f fence-agents-debugsource-4.10.0-43.el9_2.24.ppc64le.rpm SHA-256: be27b651ecad5cc9961cadd26a80a3855b739fcb515cf7b6a6563ff8b0096e20 fence-agents-ibm-powervs-4.10.0-43.el9_2.24.noarch.rpm SHA-256: f429232ef915f8d0be74155c7a9031caf1b235a9a3b167d781fc98c4f281040a fence-agents-ibm-vpc-4.10.0-43.el9_2.24.noarch.rpm SHA-256: 867109528b014fa079351d5cee2920b91111af9c20fb04beaf17c4eff1bcea5d fence-agents-kdump-debuginfo-4.10.0-43.el9_2.24.ppc64le.rpm SHA-256: d4fd04840a8fe834cea826d314972de1f35e4eeae397eddaeeab0c785abba950 fence-agents-kubevirt-4.10.0-43.el9_2.24.ppc64le.rpm SHA-256: 096420db97039a52f1544a931df4ab27eba7eaf597c39fc476af1ce823294d41 fence-agents-kubevirt-debuginfo-4.10.0-43.el9_2.24.ppc64le.rpm SHA-256: d9883bae6ac5a49efc34ad1bc9967ced6ed898948dd67de25bf116cd5499168e fence-agents-virsh-4.10.0-43.el9_2.24.noarch.rpm SHA-256: f7f96e1d076d985b6c64e407dd214a13a04c8582ce8b03e928f703d4eff72bbf Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 9.2 SRPM ppc64le fence-agents-all-4.10.0-43.el9_2.24.ppc64le.rpm SHA-256: 59986a8d0b01da46f0bd838893afd0be0e0c15110949f23f91ece65274a649d9 fence-agents-amt-ws-4.10.0-43.el9_2.24.noarch.rpm SHA-256: 0cdfa0237b068e697ed0c04dfac489521d548f9bb3a1b3798e09d6cca94aab08 fence-agents-apc-4.10.0-43.el9_2.24.noarch.rpm SHA-256: 2d7e76d1aeb19132f7ab3c759a1a0b03390400d8487c7200d4cfe293662f12d1 fence-agents-apc-snmp-4.10.0-43.el9_2.24.noarch.rpm SHA-256: 5194810455974833157030b7ebe7a7d43fff678665eb42fc9da2c829cba4ecbb fence-agents-bladecenter-4.10.0-43.el9_2.24.noarch.rpm SHA-256: e6ad5ec534442093743d3be5de046c5505506666506d0a08381bf2ef5d9f11a6 fence-agents-brocade-4.10.0-43.el9_2.24.noarch.rpm SHA-256: 5793342d151ef8fe7e5c66d18399c2e2dcf1f5b6d7b298325eab0f202132b485 fence-agents-cisco-mds-4.10.0-43.el9_2.24.noarch.rpm SHA-256: 4b2e2060330501ee7d30b8da444eca25ff1355085529c61e7bc501c40dca333a fence-agents-cisco-ucs-4.10.0-43.el9_2.24.noarch.rpm SHA-256: 4b9e75f0c260e728580cffd9729c3f5e39ddef841582b88b55fb660236c783e6 fence-agents-debuginfo-4.10.0-43.el9_2.24.ppc64le.rpm SHA-256: 98a553c3b04b148edcaa3fbd61623393df51f85bdcade437f2c08d94c411ab3f fence-agents-debugsource-4.10.0-43.el9_2.24.ppc64le.rpm SHA-256: be27
A vulnerability (CVE-2026-59939, CVSS 7.5 HIGH) in the httplib2 library allows a denial-of-service attack via unbounded decompression of HTTP response bodies. The affected fence-agents package for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions includes a vulnerable version of httplib2, specifically versions prior to 0.32.0. The fix is included in the provided Red Hat security update, which upgrades the underlying httplib2 component to version 0.32.0.