A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
https://access.redhat.com/errata/RHSA-2026:43606
https://access.redhat.com/errata/RHSA-2026:42076
https://access.redhat.com/errata/RHSA-2026:42075
https://access.redhat.com/errata/RHSA-2026:42041
https://access.redhat.com/errata/RHSA-2026:41044
https://access.redhat.com/errata/RHSA-2026:41043
https://access.redhat.com/errata/RHSA-2026:41042
https://access.redhat.com/errata/RHSA-2026:41041
https://access.redhat.com/errata/RHSA-2026:40833