Red Hat Security Advisory: fence-agents security update
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * fence-agents: Jinja has a sandbox breakout through indirect reference to format method [rhel-9.5.z] (CVE-2024-56326) * fence-agents: Jinja has a sandbox breakout through malicious filenames [rhel-9.5.z] (CVE-2024-56201)
AI Analysis
Technical Summary
The fence-agents packages in Red Hat Enterprise Linux 9 contain two security flaws related to the Jinja templating engine sandbox. CVE-2024-56201 allows sandbox breakout through malicious filenames, while CVE-2024-56326 enables sandbox breakout via indirect references to the format method. These vulnerabilities could allow an attacker to bypass sandbox restrictions within fence-agents scripts, which manage remote power control of cluster nodes. Red Hat has released updates for fence-agents to fix these issues in Red Hat Enterprise Linux 9.
Potential Impact
Successful exploitation of these vulnerabilities could allow an attacker to escape the Jinja sandbox in fence-agents, potentially leading to unauthorized code execution or manipulation within the context of cluster remote power management. This could affect the stability and security of cluster operations by enabling forced restarts or removals of nodes under attacker control. The severity is rated high by Red Hat.
Mitigation Recommendations
Red Hat has released security updates for fence-agents in Red Hat Enterprise Linux 9 to address these vulnerabilities. Users should apply the updates as described in the Red Hat advisory RHSA-2025:0308 and the referenced article https://access.redhat.com/articles/11258. No additional mitigation steps are indicated beyond applying the official patches.
Red Hat Security Advisory: fence-agents security update
Description
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * fence-agents: Jinja has a sandbox breakout through indirect reference to format method [rhel-9.5.z] (CVE-2024-56326) * fence-agents: Jinja has a sandbox breakout through malicious filenames [rhel-9.5.z] (CVE-2024-56201)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The fence-agents packages in Red Hat Enterprise Linux 9 contain two security flaws related to the Jinja templating engine sandbox. CVE-2024-56201 allows sandbox breakout through malicious filenames, while CVE-2024-56326 enables sandbox breakout via indirect references to the format method. These vulnerabilities could allow an attacker to bypass sandbox restrictions within fence-agents scripts, which manage remote power control of cluster nodes. Red Hat has released updates for fence-agents to fix these issues in Red Hat Enterprise Linux 9.
Potential Impact
Successful exploitation of these vulnerabilities could allow an attacker to escape the Jinja sandbox in fence-agents, potentially leading to unauthorized code execution or manipulation within the context of cluster remote power management. This could affect the stability and security of cluster operations by enabling forced restarts or removals of nodes under attacker control. The severity is rated high by Red Hat.
Mitigation Recommendations
Red Hat has released security updates for fence-agents in Red Hat Enterprise Linux 9 to address these vulnerabilities. Users should apply the updates as described in the Red Hat advisory RHSA-2025:0308 and the referenced article https://access.redhat.com/articles/11258. No additional mitigation steps are indicated beyond applying the official patches.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:0308
- Cve Count
- 2
- Additional Cves
- ["CVE-2024-56326"]
Threat ID: 6a1f4e92e29bf47b50085e7d
Added to database: 06/02/2026, 21:43:46 UTC
Last enriched: 08/11/2026, 20:45:56 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 66
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.