fence-agents-4.2.1-129.el8_10.25
エラータID: AXSA:2026-538:07
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster.
Security Fix(es):
* cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves (CVE-2026-26007)
* pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 ?4.1.11 MUST violation) (CVE-2026-32597)
* pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-26007
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.
CVE-2026-30922
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.
CVE-2026-32597
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.
Update packages.
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticCurvePublicNumbers.public_key(), load_der_public_key() and load_pem_public_key() functions do not verify that the point belongs to the expected prime-order subgroup of the curve. This missing validation allows an attacker to provide a public key point P from a small-order subgroup. This can lead to security issues in various situations, such as the most commonly used signature verification (ECDSA) and shared key negotiation (ECDH). When the victim computes the shared secret as S = [victim_private_key]P via ECDH, this leaks information about victim_private_key mod (small_subgroup_order). For curves with cofactor > 1, this reveals the least significant bits of the private key. When these weak public keys are used in ECDSA , it's easy to forge signatures on the small subgroup. Only SECT curves are impacted by this. This vulnerability is fixed in 46.0.5.
pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An attacker can supply a crafted payload containing thousands of nested `SEQUENCE` (`0x30`) or `SET` (`0x31`) tags with "Indefinite Length" (`0x80`) markers. This forces the decoder to recursively call itself until the Python interpreter crashes with a `RecursionError` or consumes all available memory (OOM), crashing the host application. This is a distinct vulnerability from CVE-2026-23490 (which addressed integer overflows in OID decoding). The fix for CVE-2026-23490 (`MAX_OID_ARC_CONTINUATION_OCTETS`) does not mitigate this recursion issue. Version 0.6.3 fixes this specific issue.
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.
N/A
SRPMS
- fence-agents-4.2.1-129.el8_10.25.src.rpm
MD5: 2cfa19dec12465765290a54391d9575c
SHA-256: 49de2b6c73e9913462aef5231b0ceca33fa9d59428bb864d6fddfc3f6709732c
Size: 39.93 MB
Asianux Server 8 for x86_64
- fence-agents-aliyun-4.2.1-129.el8_10.25.x86_64.rpm
MD5: a82cecae821fbfabc8a07c67afe355df
SHA-256: f995a803327ed8cc21c4028993f8d7e90e023947b719acdb3236d7fda4b0ae1f
Size: 2.51 MB - fence-agents-all-4.2.1-129.el8_10.25.x86_64.rpm
MD5: 9ead4d7c945a2a20649f7b2ba04b2406
SHA-256: 9a5c34781fad0d20b04536e907273477e25826c9a4f1c1e21e9653b4c7206f84
Size: 28.32 kB - fence-agents-amt-ws-4.2.1-129.el8_10.25.noarch.rpm
MD5: 0cd83d710d9b399bd134e936ddace982
SHA-256: b002fb2da26a0cc826aab110c19f4e81e152861590ad439f0648131bbdc31e09
Size: 31.79 kB - fence-agents-apc-4.2.1-129.el8_10.25.noarch.rpm
MD5: 7c12d71f758af64d34b74fbbda5757d2
SHA-256: 7a1ad0ecb9f0bb3186a3c06ab80c38bd45512a62ae8bef4fd6a96c864dab01dd
Size: 31.88 kB - fence-agents-apc-snmp-4.2.1-129.el8_10.25.noarch.rpm
MD5: 3caabb0b6d592e00a0e62f7f4ddd3431
SHA-256: 6bd79adfb6849292ae3ea2c266a91c34c8290aa760006499368e22fb2ef75c0b
Size: 31.85 kB - fence-agents-aws-4.2.1-129.el8_10.25.noarch.rpm
MD5: ce2d70b85fb13b5ba38302ae7f76ee3e
SHA-256: 940250bca336b840e38647fbef5fb51d863d7eb94c67f8f832ee22d0fc4279ef
Size: 6.74 MB - fence-agents-azure-arm-4.2.1-129.el8_10.25.x86_64.rpm
MD5: d31c60e883a4c20d5fc8eb5c41a88be8
SHA-256: 8f163b0f5f2bc25aa239565526d155b3997e72a02217ada29c0764048df71368
Size: 18.33 MB - fence-agents-bladecenter-4.2.1-129.el8_10.25.noarch.rpm
MD5: 856a6d39ebf5da32158877b5b9fc118b
SHA-256: c60faf5df3125a1cde9ccc542fa1e2e78a58d847ed5c261184ca904f9d89c0cf
Size: 30.94 kB - fence-agents-brocade-4.2.1-129.el8_10.25.noarch.rpm
MD5: 92de8d7f741ea3dbe12e4706aa7f3082
SHA-256: b3e9d0fc7720a815ca219c69881886b484326691a516c378744dfe67bb926182
Size: 31.05 kB - fence-agents-cisco-mds-4.2.1-129.el8_10.25.noarch.rpm
MD5: 289d8fdf89e2721909ced83821f76d40
SHA-256: f3c4bcfda6b4ee8c1972b1236f45cf259867be4c97d1b5113322b15474191fc9
Size: 30.87 kB - fence-agents-cisco-ucs-4.2.1-129.el8_10.25.noarch.rpm
MD5: df71ffbe196dcad4e508bc64c406e3b5
SHA-256: be805a7191f94958e19a0e393ab2c84a942768201740037acd5339bc89972e46
Size: 31.53 kB - fence-agents-common-4.2.1-129.el8_10.25.noarch.rpm
MD5: d1b87b6620011c1770eec9752ae1f845
SHA-256: 39e6c7cede74c60591f3607e53d32e0e95b420e5c6c86327f84eeed31cd91c20
Size: 74.99 kB - fence-agents-compute-4.2.1-129.el8_10.25.noarch.rpm
MD5: f41a02716404d4ea7d8efb0c368694cf
SHA-256: ea25fde856bb3e96301f1472568e14ee9b51adc1eb113d87170666ac284db552
Size: 38.06 kB - fence-agents-drac5-4.2.1-129.el8_10.25.noarch.rpm
MD5: cae4d40ae943cba3783203a5d7765d7b
SHA-256: b64a04a364917fff8c32010c3a5cff5c7b9f22b4c285d1d0a3cd5a114d18a3e1
Size: 31.53 kB - fence-agents-eaton-snmp-4.2.1-129.el8_10.25.noarch.rpm
MD5: 7eac8db24b46d62b9e69818bd069e003
SHA-256: c317c5daa931443038d5deaaf22bf0ec7dd1a87fb1eae0a26e47417495f02289
Size: 32.05 kB - fence-agents-emerson-4.2.1-129.el8_10.25.noarch.rpm
MD5: b910701a522689057b0ef60a39ef6c24
SHA-256: 9cafdec77398094cceedbee0dcbf9a421baaa8bd37dec3aec3c797d28e9749bc
Size: 30.45 kB - fence-agents-eps-4.2.1-129.el8_10.25.noarch.rpm
MD5: da2ee0d39ee3048a32f7e491d8696817
SHA-256: c435adb679a286a734d03c186c45787b6fd13358e8fbe4b5541a1a6e43073021
Size: 33.34 kB - fence-agents-gce-4.2.1-129.el8_10.25.noarch.rpm
MD5: b4d2235511a14e849a6a1ba177c099db
SHA-256: 971c5228d0662d36ba5e6686ee1960697782f016c2295d8d90afc10ba0d6b7a1
Size: 255.19 kB - fence-agents-heuristics-ping-4.2.1-129.el8_10.25.noarch.rpm
MD5: 22fc5332b878b4aa31879cad244105f6
SHA-256: bbb8322197c19830f2e246614915fa395542a938cd994db17ef826f84b34293d
Size: 31.32 kB - fence-agents-hpblade-4.2.1-129.el8_10.25.noarch.rpm
MD5: 9f745d04cce0b0e7f44eb3a3d139fb0c
SHA-256: 364addf49a2998ae40f13cc1ef75650d8e6422d1ef576ca0a1a444118ca69e98
Size: 31.06 kB - fence-agents-ibmblade-4.2.1-129.el8_10.25.noarch.rpm
MD5: 3c5ab04ee1072974dbabb840d2a0db7e
SHA-256: 5cb9b7b54bd44ea782877c8790571fad64fd3e759011ae65f45384044086a6a5
Size: 30.59 kB - fence-agents-ibm-powervs-4.2.1-129.el8_10.25.noarch.rpm
MD5: 402e51d870be1d9595f0c9421af0d315
SHA-256: 82a91d123ec1f4655c699ce9ac31e062d92e8832f15b06cdab693064f29dcc8a
Size: 31.82 kB - fence-agents-ibm-vpc-4.2.1-129.el8_10.25.noarch.rpm
MD5: eb448740049ee4bdff87ed9eb7f3928b
SHA-256: 2b2ccd732e4d1a5de92b4363c4871267f5c92fe51692063ecb8cb64c65b0df8f
Size: 32.29 kB - fence-agents-ifmib-4.2.1-129.el8_10.25.noarch.rpm
MD5: b852d6e9ad5ff6bcf4ddb8453b942cd8
SHA-256: fdc937100c7b027a636bfb555bbbd6a4463e8a02af7339c96eef0c7ce8f5d428
Size: 31.19 kB - fence-agents-ilo2-4.2.1-129.el8_10.25.noarch.rpm
MD5: 4007a2ce19715c536c76c1ed3cbf2ac0
SHA-256: 0bc591e089fd18cacacef9f2daab93aff56a2e916c5ef21edb3d40c6f629cbfd
Size: 33.16 kB - fence-agents-ilo-moonshot-4.2.1-129.el8_10.25.noarch.rpm
MD5: 6aba32ec2842d58a1b2b08ae97c850ac
SHA-256: abf4403108a11fb0bbc872f64410e450933798c94feb559c1655c1aed274ea2e
Size: 30.38 kB - fence-agents-ilo-mp-4.2.1-129.el8_10.25.noarch.rpm
MD5: 812bc890977b47e46f15e9a709bf4833
SHA-256: b5ba03d6f5a9b59cc24c2c39c4704944675868ad2beeb39af76a6d10512e7291
Size: 30.17 kB - fence-agents-ilo-ssh-4.2.1-129.el8_10.25.noarch.rpm
MD5: b94d2e99120f48a24020da43d07fafe2
SHA-256: 28b626da9cba0ff5c342ee93e849a6e11336ec79b3a8b274a77d2f13dded7add
Size: 36.88 kB - fence-agents-intelmodular-4.2.1-129.el8_10.25.noarch.rpm
MD5: b4a1564e9c3e3e599c081ba111933ac8
SHA-256: b1682aaffb0767ae8f9a43c4534227864d30b5e820bef06540248713bd651ede
Size: 31.00 kB - fence-agents-ipdu-4.2.1-129.el8_10.25.noarch.rpm
MD5: af51e2bb3883acd3390545b2343d7135
SHA-256: cd5478311fffb32e718f8b9a70721bb0a004793d3c4689ece3485b11a22904aa
Size: 31.22 kB - fence-agents-ipmilan-4.2.1-129.el8_10.25.noarch.rpm
MD5: fdfbf7da9d51d199b0d6e4ab8fd22393
SHA-256: 6cf10569f82aa12928d6da8e572cb0a97bafecada89e466cd5b8ca764f7d7e1f
Size: 44.71 kB - fence-agents-kdump-4.2.1-129.el8_10.25.x86_64.rpm
MD5: f55fcb962ff6b22dd51a2d4158256db8
SHA-256: 85340af3a87445705016a69ca078e3048b55a4f9bc71cb6f1c12fcabbf3299f4
Size: 43.23 kB - fence-agents-kubevirt-4.2.1-129.el8_10.25.x86_64.rpm
MD5: 076c3ff8c5172c7f3a690db3dab175ee
SHA-256: 97c3b974be3b67d4f02b52c7286b2a637be519284aceab4434ec550c2f393790
Size: 4.47 MB - fence-agents-lpar-4.2.1-129.el8_10.25.noarch.rpm
MD5: 48271dfd7ad14d99991d592449e27e90
SHA-256: b9e2343e07dfecfa357432b6c87838bc1e745e7b17573197c18c4a056729ee17
Size: 31.43 kB - fence-agents-mpath-4.2.1-129.el8_10.25.noarch.rpm
MD5: 3847f7b12b4808840478ebcd432ed92d
SHA-256: a4c83054a75adbc3c20c71df9fb1396e20bc2f8b74c02bd06d24b258dc8b248a
Size: 33.60 kB - fence-agents-nutanix-ahv-4.2.1-129.el8_10.25.noarch.rpm
MD5: a5411d69b94eb580b049de6c9f3c73dd
SHA-256: 5330e3e3b712a2993a8e44f836609c8497998f4ac1c5586a1f6701f0286f1a54
Size: 33.39 kB - fence-agents-openstack-4.2.1-129.el8_10.25.x86_64.rpm
MD5: 545d05ae2bed4c28f34a0a3f950e7aa8
SHA-256: c31cbc11f3f30fcdbb2dda6f55c35a89e016148fc86bb921c966f8585935cf36
Size: 32.54 kB - fence-agents-redfish-4.2.1-129.el8_10.25.x86_64.rpm
MD5: f0cc3ea862a7ca3446c353fc9d2cd4b0
SHA-256: 163b5e16efdf38aa7cb9c8dccdba2bd76a22d9afb4215ba3f136719c7cf10eaa
Size: 31.47 kB - fence-agents-rhevm-4.2.1-129.el8_10.25.noarch.rpm
MD5: d6d2bc11ef62d53686fd6a6f39ffc8fd
SHA-256: ade2cbad4563155a8c707198ee622ff1d74c7214d3ecdbd6023a2964a818cd7e
Size: 31.80 kB - fence-agents-rsa-4.2.1-129.el8_10.25.noarch.rpm
MD5: 42bb3a01879a3f433278372c5ce35843
SHA-256: cdd81fdf7bedaa768fcae81eede8e12abbae3d386601dca64674fb3af06f31af
Size: 30.51 kB - fence-agents-rsb-4.2.1-129.el8_10.25.noarch.rpm
MD5: fbcaaad91a208cef8c46da09839f1d1b
SHA-256: 1a19b2601dcc759e05e17a236d0f99895dd19bc20487dcb5c462f595de250ffd
Size: 30.54 kB - fence-agents-sbd-4.2.1-129.el8_10.25.noarch.rpm
MD5: 57f63c69d6624b3108b5121d71058bf3
SHA-256: e90e4d17af28d94f1beb82b5392dcd6bf6915e9b6b0d66778816e034774eacd9
Size: 32.29 kB - fence-agents-scsi-4.2.1-129.el8_10.25.noarch.rpm
MD5: c113081f361f5389a702faa03d72dbbb
SHA-256: 2cf97edf56c876293314e82886c8b8322e54f21c213582c10b398dcf8614cfc2
Size: 36.12 kB - fence-agents-virsh-4.2.1-129.el8_10.25.noarch.rpm
MD5: 8d2b9c3cbdd5744484557cd8d208f212
SHA-256: 5900e2e57beede4dc550bfa77ff978c22083da82c3fc2ec500cb5e38b12898fa
Size: 31.14 kB - fence-agents-vmware-rest-4.2.1-129.el8_10.25.noarch.rpm
MD5: 36300e63f7827b76fcc0a718d7f7b3d0
SHA-256: 772835c10e56bbf29e7a28bd2aeb24e725ad89ef61fd16c5cef82edabbd49ace
Size: 31.71 kB - fence-agents-vmware-soap-4.2.1-129.el8_10.25.noarch.rpm
MD5: df4dbd9027b613aca9443f3ba7d9d1a6
SHA-256: d619e29d9bdbb932b9b8a2e607439e71a801445b6fb9816020af57b6840a1248
Size: 32.73 kB - fence-agents-wti-4.2.1-129.el8_10.25.noarch.rpm
MD5: 9ff3d574d0d50b6ff2eb8b34a0b6ee90
SHA-256: 892c8996b74c926ad422b8a2c19714d2cec2ceb38c49957803331a27d66bef87
Size: 32.14 kB