RHSA-2021:4139: Moderate: resource-agents security, bug fix, and enhancement update
The resource-agents packages provide the Pacemaker and RGManager service managers with a set of scripts. These scripts interface with several services to allow operating in a high-availability (HA) environment.Security Fix(es): python-pygments: Infinite loop in SML lexer may lead to DoS (CVE-2021-20270) python-pygments: ReDoS in multiple lexers (CVE-2021-27291) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:4139?
The severity of RHSA-2021:4139 is classified as moderate.
How do I fix RHSA-2021:4139?
To fix RHSA-2021:4139, update the resource-agents packages to version 4.1.1-98.el8 or later.
What vulnerabilities does RHSA-2021:4139 address?
RHSA-2021:4139 addresses vulnerabilities related to an infinite loop in the SML lexer of python-pygments.
Which systems are affected by RHSA-2021:4139?
RHSA-2021:4139 affects Red Hat Enterprise Linux 8 systems using the resource-agents packages.
Are there specific packages that need to be updated for RHSA-2021:4139?
Yes, specific packages such as resource-agents, resource-agents-aliyun, and resource-agents-gcp need to be updated.