Oval Definition:oval:com.redhat.rhsa:def:20151424
Revision Date:2015-07-22Version:646
Title:RHSA-2015:1424: pacemaker security and bug fix update (Moderate)
Description:The Pacemaker Resource Manager is a collection of technologies working together to provide data integrity and the ability to maintain application availability in the event of a failure.

  • A flaw was found in the way pacemaker, a cluster resource manager, evaluated added nodes in certain situations. A user with read-only access could potentially assign any other existing roles to themselves and then add privileges to other users as well. (CVE-2015-1867)

    This update also fixes the following bugs:

  • Due to a race condition, nodes that gracefully shut down occasionally had difficulty rejoining the cluster. As a consequence, nodes could come online and be shut down again immediately by the cluster. This bug has been fixed, and the "shutdown" attribute is now cleared properly. (BZ#1198638)

  • Prior to this update, the pacemaker utility caused an unexpected termination of the attrd daemon after a system update to Red Hat Enterprise Linux 6.6. The bug has been fixed so that attrd no longer crashes when pacemaker starts. (BZ#1205292)

  • Previously, the access control list (ACL) of the pacemaker utility allowed a role assignment to the Cluster Information Base (CIB) with a read-only permission. With this update, ACL is enforced and can no longer be bypassed by the user without the write permission, thus fixing this bug. (BZ#1207621)

  • Prior to this update, the ClusterMon (crm_mon) utility did not trigger an external agent script with the "-E" parameter to monitor the Cluster Information Base (CIB) when the pacemaker utility was used. A patch has been provided to fix this bug, and crm_mon now calls the agent script when the "-E" parameter is used. (BZ#1208896)

    Users of pacemaker are advised to upgrade to these updated packages, which contain backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-1867
    RHSA-2015:1424
    RHSA-2015:1424-01
    RHSA-2015:1424-03
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • pacemaker is earlier than 0:1.1.12-8.el6
  • AND pacemaker is signed with Red Hat redhatrelease2 key
  • pacemaker-cli is earlier than 0:1.1.12-8.el6
  • AND pacemaker-cli is signed with Red Hat redhatrelease2 key
  • pacemaker-cluster-libs is earlier than 0:1.1.12-8.el6
  • AND pacemaker-cluster-libs is signed with Red Hat redhatrelease2 key
  • pacemaker-cts is earlier than 0:1.1.12-8.el6
  • AND pacemaker-cts is signed with Red Hat redhatrelease2 key
  • pacemaker-doc is earlier than 0:1.1.12-8.el6
  • AND pacemaker-doc is signed with Red Hat redhatrelease2 key
  • pacemaker-libs is earlier than 0:1.1.12-8.el6
  • AND pacemaker-libs is signed with Red Hat redhatrelease2 key
  • pacemaker-libs-devel is earlier than 0:1.1.12-8.el6
  • AND pacemaker-libs-devel is signed with Red Hat redhatrelease2 key
  • pacemaker-remote is earlier than 0:1.1.12-8.el6
  • AND pacemaker-remote is signed with Red Hat redhatrelease2 key
  • BACK