fence-agents-4.2.1-129.el8_10.24
エラータID: AXBA:2026-269:05
リリース日:
2026/03/06 Friday - 17:12
題名:
fence-agents-4.2.1-129.el8_10.24
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
N/A
解決策:
Update packages.
CVE:
CVE-2025-66418
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.
CVE-2025-66471
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.
CVE-2026-21441
urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.
urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.
追加情報:
N/A
ダウンロード:
SRPMS
- fence-agents-4.2.1-129.el8_10.24.src.rpm
MD5: e2a8f1aa670de2a0f231263ed40201cb
SHA-256: 8957abe6427e09a4df8d00f6e2e8a537ccaa3aea31c385418f1a0a18a73f416b
Size: 39.93 MB
Asianux Server 8 for x86_64
- fence-agents-aliyun-4.2.1-129.el8_10.24.x86_64.rpm
MD5: 2b5a3c32f2d47191d2ef130b2be2520d
SHA-256: e6cc1843b92cc9a8ab87d9d295b355ad9e0c17d6b042f3df4f989849eb0800a6
Size: 2.51 MB - fence-agents-all-4.2.1-129.el8_10.24.x86_64.rpm
MD5: 5208c13ddd539e6119e37b1fe04c856a
SHA-256: efc5e323e93e083034e182505a81891c3440487c485b3f0bb6730610063d0c5c
Size: 28.05 kB - fence-agents-amt-ws-4.2.1-129.el8_10.24.noarch.rpm
MD5: 24e92b3b0b03a7e31f0db7f416171ecd
SHA-256: f413530088efe02a69f4d8c829229891c167c43d1fc19644f01383839a5994ae
Size: 31.52 kB - fence-agents-apc-4.2.1-129.el8_10.24.noarch.rpm
MD5: 383d811aff37739236b267ee2c0c07e0
SHA-256: 303f6a647c84e4c5da2120f70cc1e46effe0569440742c7d168b8e27b36c0757
Size: 31.61 kB - fence-agents-apc-snmp-4.2.1-129.el8_10.24.noarch.rpm
MD5: 2ab7631acad3927cf2d5720605ed92d3
SHA-256: 527f3e91f99eac5901aac6c669bb89d093be3c74412694446e3df481599d7faa
Size: 31.58 kB - fence-agents-aws-4.2.1-129.el8_10.24.noarch.rpm
MD5: 69df4c32e32e09ec9ce5b237128dec05
SHA-256: 53299df95cb95cbd5d8da45f31b82467095a9630835b1a57e6482145d01e9cd3
Size: 6.74 MB - fence-agents-azure-arm-4.2.1-129.el8_10.24.x86_64.rpm
MD5: 369d7828175a81acf933fb8ab6c791c8
SHA-256: fec79a6ca95ba7cfb4d2e26ca3539b3a8290bfb6ea5a5ffdb0c1cdbc020e6530
Size: 18.75 MB - fence-agents-bladecenter-4.2.1-129.el8_10.24.noarch.rpm
MD5: 6c7db9b5da08f2ce5333a32178ada114
SHA-256: 1e744a3ae2663915655415ccd3f7b35369d55aa5112687ac6478c363db5a8b8c
Size: 30.66 kB - fence-agents-brocade-4.2.1-129.el8_10.24.noarch.rpm
MD5: 0f25d8e2154e5148999fdd98910bde39
SHA-256: eaf7b366c962445f734e70036f06ad350ff98165540ff032f2143d12659aabdb
Size: 30.78 kB - fence-agents-cisco-mds-4.2.1-129.el8_10.24.noarch.rpm
MD5: 9ddac84b1b55b6c2baf026d44ed75623
SHA-256: 480fd431688cdd3047c694348d4462f239ca2e93505ec30c97ac513c4fc1620b
Size: 30.59 kB - fence-agents-cisco-ucs-4.2.1-129.el8_10.24.noarch.rpm
MD5: a93836447798abb681130d90e1407b97
SHA-256: 6516d7d17f2cfa38213ea6adc9c674ebfcd78f3a46f698010f222f60240865e0
Size: 31.26 kB - fence-agents-common-4.2.1-129.el8_10.24.noarch.rpm
MD5: 21e32afd2ecf0aadab77c1b01e9fc836
SHA-256: af7018f051b1df6921413fd9b51aae695198c59bd333949252176b241909c081
Size: 74.72 kB - fence-agents-compute-4.2.1-129.el8_10.24.noarch.rpm
MD5: b821072eb33b5a3bf6c10f36edf3b60d
SHA-256: b4c35b71391d0ad3975e16b40a79d848e0e02b08b80104310c3239321956e3b9
Size: 37.79 kB - fence-agents-drac5-4.2.1-129.el8_10.24.noarch.rpm
MD5: b686ce793e82b005c7148a66bc7b3fec
SHA-256: 68e3b8fe1a415445c457b5693f9f36a63ad9f320d78262e16c623fd90e8c3176
Size: 31.26 kB - fence-agents-eaton-snmp-4.2.1-129.el8_10.24.noarch.rpm
MD5: 1d68b79efd500a4aec22951ee32af638
SHA-256: 47440d91f1390fe8458ad93defed200915dbbc83f0c59ca19921c7fb9f0e7716
Size: 31.77 kB - fence-agents-emerson-4.2.1-129.el8_10.24.noarch.rpm
MD5: 26083f3103fe8aba669da4d2ae3d0f16
SHA-256: ca330c189bc144eb4a14af879d1195e4455ecd0221f6f7bc49c48003dad6f8a4
Size: 30.18 kB - fence-agents-eps-4.2.1-129.el8_10.24.noarch.rpm
MD5: a073257c49938734a1a8b8034290d56f
SHA-256: 9e5c083e1e2955c3083175b16ff3143a45a3227ebd2f33891ccfba2cebf557e6
Size: 33.07 kB - fence-agents-gce-4.2.1-129.el8_10.24.noarch.rpm
MD5: d718506bb882610220bef74b3c2f165e
SHA-256: 65e84ea736cc7a3b0d1f59cc57b27a392e0b93a82e59f58950287aa09c80c9e9
Size: 254.92 kB - fence-agents-heuristics-ping-4.2.1-129.el8_10.24.noarch.rpm
MD5: bf0b8af888728047557ab956767ea4a5
SHA-256: 05c920ce6aab4453c0124b7cd1fe60df9da82c45ca6983e8711fc8b516f8b2f3
Size: 31.05 kB - fence-agents-hpblade-4.2.1-129.el8_10.24.noarch.rpm
MD5: 1a09baf3e45f2aaaf18e175c306a1a73
SHA-256: 3543cfa6b02a56a17ba9cdefe84e0a5e608ff6215faea990ac821dacd22e660a
Size: 30.79 kB - fence-agents-ibmblade-4.2.1-129.el8_10.24.noarch.rpm
MD5: 707d429ddc8b211ab26e535cd8bfc44b
SHA-256: acefa1a0266c10da8075674541118ae20d1a6021eb5de8e40702c486a105aa96
Size: 30.32 kB - fence-agents-ibm-powervs-4.2.1-129.el8_10.24.noarch.rpm
MD5: 69c171592abe15f65bb02a9c018805ce
SHA-256: 1372dc260d4b534957381d71b26b1ed20882639f895761fb7eb70115465b3fc7
Size: 31.55 kB - fence-agents-ibm-vpc-4.2.1-129.el8_10.24.noarch.rpm
MD5: f75ec5ee9936dfbbc9e9233063b8c1d4
SHA-256: 8f391b48753d4db1d1cc640cca86bdccaebd5cc4e60d70f739f2782d321426e1
Size: 32.02 kB - fence-agents-ifmib-4.2.1-129.el8_10.24.noarch.rpm
MD5: b36c31e537f30bbfe0ec17b0634ca6d6
SHA-256: 1c4074a2381e0e4a29f6238ed1d4759cb18fc558c037aaa9b4938564245a6032
Size: 30.92 kB - fence-agents-ilo2-4.2.1-129.el8_10.24.noarch.rpm
MD5: 826ef5a2f3207cb2aa1c2f28d594b673
SHA-256: ca8cc524647817bc571920f767941274398ed352191043bfac87453003763799
Size: 32.89 kB - fence-agents-ilo-moonshot-4.2.1-129.el8_10.24.noarch.rpm
MD5: e74c604930f5ed54c86fb715f273234d
SHA-256: b9c13c588bd428eae874ad75a5379501a6e21c96548663b334559d134aaba6a3
Size: 30.11 kB - fence-agents-ilo-mp-4.2.1-129.el8_10.24.noarch.rpm
MD5: 38272343f94c3d4024733650121cbd4f
SHA-256: 891621f50cb58503ea520425155f342e6801256b660bf49f494d3109943c354a
Size: 29.90 kB - fence-agents-ilo-ssh-4.2.1-129.el8_10.24.noarch.rpm
MD5: 623d6eb69ad64b7544c72e2b9510cc1d
SHA-256: 3251c99ee4fc52bf55e5a6838062c4f406fe4865eafda2a9bb8a1b7a140d9f2d
Size: 36.61 kB - fence-agents-intelmodular-4.2.1-129.el8_10.24.noarch.rpm
MD5: 1407d3a26441de067e4d989463a46955
SHA-256: d81362eee117f4be3f9be92b39c5b29b790925be8e168bbb366cab210f7b7283
Size: 30.73 kB - fence-agents-ipdu-4.2.1-129.el8_10.24.noarch.rpm
MD5: 77a4e772ea2ef531e241210bc5d05580
SHA-256: 6721654f86806b94c256efcfdc58cf17b2fd8a2e695ebd25bc0905230226a2d9
Size: 30.95 kB - fence-agents-ipmilan-4.2.1-129.el8_10.24.noarch.rpm
MD5: bce9df0d3efd6efb75121322c8f4f91b
SHA-256: f1580c7aae8b2835d0ca4d390af36638ad33d48800289e0a2ff15e61b38c0c2d
Size: 44.44 kB - fence-agents-kdump-4.2.1-129.el8_10.24.x86_64.rpm
MD5: ecb5f012731aad0592e94c4ba6f78133
SHA-256: fe9d32338cd8eb766528b86f93425defbcf7fdd73a54fb6bb5e94c24755de125
Size: 42.81 kB - fence-agents-kubevirt-4.2.1-129.el8_10.24.x86_64.rpm
MD5: b907a27aa6f08241a69a02a3beb8dbbc
SHA-256: bd97e63565e4ee61960796729dd5af8d438c59811579bd93746d07c8d66bb4fc
Size: 4.47 MB - fence-agents-lpar-4.2.1-129.el8_10.24.noarch.rpm
MD5: af5c0c2e2822c727abf832f8896b92f7
SHA-256: d66b5b8fac11e1befe9cd1d633f4cab63c2c46f4a96b5712cc3f29bf82e411d6
Size: 31.16 kB - fence-agents-mpath-4.2.1-129.el8_10.24.noarch.rpm
MD5: 186dc47a891cf3fb98ba5be32e7264f8
SHA-256: 662a3a236981762ca3cb87cb5a02731e03dbe18b203dc1751af7663b53cffac8
Size: 33.33 kB - fence-agents-nutanix-ahv-4.2.1-129.el8_10.24.noarch.rpm
MD5: 2b430582d2e638fc6759250f47d89da1
SHA-256: 006faf07cc96120d798b730558009a0f2e69c154853417157df25727e4ec6362
Size: 33.12 kB - fence-agents-openstack-4.2.1-129.el8_10.24.x86_64.rpm
MD5: 685cc67b2fa310aab0e2acbe36388451
SHA-256: 7e09c12ba9ff06ec7ee8fcfdb5251ae0087a21b1572c9df4dba04407191a0481
Size: 32.27 kB - fence-agents-redfish-4.2.1-129.el8_10.24.x86_64.rpm
MD5: 2095f6bc2fe2a0c428f4178e340eb85b
SHA-256: 04d50ce84aa1c6b70dcd9be9a5f7cd3d845c270d81455745f490470a60ce9ee7
Size: 31.20 kB - fence-agents-rhevm-4.2.1-129.el8_10.24.noarch.rpm
MD5: cf4a4734e681003ddd7cb89a77fd0e7b
SHA-256: 186b6df6a83a8863c212a217f2ef1df5114eabb24c8a3d09ca751af24c5f7cc3
Size: 31.54 kB - fence-agents-rsa-4.2.1-129.el8_10.24.noarch.rpm
MD5: d0bc0adf34d4c8cc5310c1cd3d3f83e9
SHA-256: 4ad986ebfbcd9686fa0f6705184c231b728d16cc77d9bfba9a6a5c15dd6f4597
Size: 30.24 kB - fence-agents-rsb-4.2.1-129.el8_10.24.noarch.rpm
MD5: 24bace269a9163a56d60a672e253874f
SHA-256: 3be118cdc39e0f9eef62e2e5348d424b11971d4d5b02ed3e78ea8bfbc7cb1ace
Size: 30.27 kB - fence-agents-sbd-4.2.1-129.el8_10.24.noarch.rpm
MD5: a91367e36ac320c993463111038ffc08
SHA-256: 6cdb3a3439e75bc27b8cbc52a3968ecad2733893b6c759a642bdcfefb2918099
Size: 32.02 kB - fence-agents-scsi-4.2.1-129.el8_10.24.noarch.rpm
MD5: 702d73ea8f1e3a94e937e684fafaba05
SHA-256: 79573e8b6e185d12c6745c353eb0bb694f1e5593de6a19ed527be2751f2c2a18
Size: 35.85 kB - fence-agents-virsh-4.2.1-129.el8_10.24.noarch.rpm
MD5: 85fc3dc4bac152a43b7a2a1f4f71d95c
SHA-256: 4dc7ed2ad302ded71f04d9376a73593ea368b183790418cf576ac4d4307111eb
Size: 30.87 kB - fence-agents-vmware-rest-4.2.1-129.el8_10.24.noarch.rpm
MD5: 8508692f38c3b43980191aac10e6d514
SHA-256: f5bf2b924cec36aa4c415da6be7c053a358354258e65b91c113e1f1126c33764
Size: 31.44 kB - fence-agents-vmware-soap-4.2.1-129.el8_10.24.noarch.rpm
MD5: 3c45c2d40e082e9ed8919fd534c25e32
SHA-256: a549407e6760e30010cf49dc5039bb4f9cad105e70353975bb48c9934582795c
Size: 32.46 kB - fence-agents-wti-4.2.1-129.el8_10.24.noarch.rpm
MD5: 32d990243b67ee2570fa1b88d26ea6ab
SHA-256: 1cb85c862ac4b2ff5b55152bf5991c7968c802cf94c43aa52f24a15798f39ef6
Size: 31.87 kB