resource-agents-4.9.0-54.el8_10.29
エラータID: AXBA:2026-270:01
Release date:
Friday, March 6, 2026 - 21:01
Subject:
resource-agents-4.9.0-54.el8_10.29
Affected Channels:
Asianux Server 8 for x86_64
Severity:
N/A
Solution:
Update packages.
CVEs:
CVE-2026-21441
urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.
urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.
Additional Info:
N/A
Download:
SRPMS
- resource-agents-4.9.0-54.el8_10.29.src.rpm
MD5: 9e6dc0b09136cfddb941adaac582ac29
SHA-256: d931f066f77a88dc0745a8bcff4f4ce10b157eb9bc354b973b0f82a0c26bf55b
Size: 95.67 MB
Asianux Server 8 for x86_64
- resource-agents-4.9.0-54.el8_10.29.x86_64.rpm
MD5: 92672383debb464ae485586aa3856cc7
SHA-256: ff3ed193e47b00007e15ee24fc91c8c0b0184f48aa211d130c56e5b8f0180f8b
Size: 552.04 kB - resource-agents-aliyun-4.9.0-54.el8_10.29.x86_64.rpm
MD5: 7d1e2a4044c4a1ccbd900e9ad97c5d76
SHA-256: bdbec9cc85fca3e3fb7e6d1f50fee3266a3f7877886923596f6be9deeac2dc52
Size: 2.66 MB - resource-agents-gcp-4.9.0-54.el8_10.29.x86_64.rpm
MD5: 8c6142111089522e1d51fe16c1cae15d
SHA-256: e7a6c982fe6ac67a56b5dd0880cdf9511c652a23d108b75394174d0500e09a2a
Size: 21.81 MB - resource-agents-paf-4.9.0-54.el8_10.29.x86_64.rpm
MD5: 87566e7bdf204d6566c9ffee02bda548
SHA-256: 5d65d7d4b41ce6d6bc484bee737dbcb0a2b8bc302f021bea69704e25b6549b7d
Size: 77.45 kB