Skip to main content
EPSS 0.7%top 48%

Red Hat Security Advisory: fence-agents security update

0
High
Published: 02/04/2026 (02/04/2026, 18:50:17 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID (CVE-2026-23490) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Affected versions
Red HatRed Hat Enterprise Linux AIRed Hat Enterprise Linux AI 3.3amd64registry.redhat.io/rhelai3/bootc-cuda-rhel9@sha256:f6f6aa6af83e4005c230be33d0ee66d1826c48bd8e1445049a1550b01a00e703_amd64Red Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 9)srcfence-agents-0:4.10.0-98.el9_7.5.srcRed Hat Enterprise Linux HighAvailability (v. 8)Red Hat Enterprise Linux ResilientStorage (v. 8)Red Hat Trusted Artifact SignerRed Hat Trusted Artifact Signer 1.3registry.redhat.io/rhtas/segment-reporting-rhel9@sha256:0e7f56263bacad63890e011c178f438f42e04c5db82b2469c80f6e5a7b77d7a8_amd64Red Hat Enterprise Linux AppStream (v. 10)fence-agents-0:4.16.0-13.el10_1.2.srcRed Hat Enterprise Linux AppStream (v. 8)Red Hat Trusted Artifact Signer 1.4registry.redhat.io/rhtas/model-transparency-rhel9@sha256:1687e39c23f2718e3b857666ba00aa7596c83810c7f43ba17170c30c95485be7_amd64Red Hat Enterprise Linux AppStream E4S (v.8.8)Red Hat Enterprise Linux High Availability E4S (v.8.8)Red Hat Enterprise Linux AppStream TUS (v.8.8)

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 19:21:29 UTC

Technical Analysis

CVE-2026-23490 is a vulnerability in the pyasn1 Python library, which is used by Red Hat fence-agents packages for remote power management in cluster environments. The vulnerability is triggered by a malformed RELATIVE-OID containing excessive continuation octets, causing uncontrolled memory allocation and exhaustion. This results in a denial of service condition by consuming excessive system resources. The issue is classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and related CWEs involving resource consumption. Red Hat has acknowledged the vulnerability and provided patches to mitigate the risk.

Potential Impact

An attacker can cause a denial of service by sending specially crafted input that triggers excessive memory allocation in the pyasn1 library. This leads to resource exhaustion, potentially making the affected system or cluster node unresponsive or unavailable. There is no impact on confidentiality or integrity reported. The severity is rated high by Red Hat due to the availability impact.

Mitigation Recommendations

Red Hat has released patches that fix this vulnerability. Users should apply the official updates provided by Red Hat to the pyasn1 library and fence-agents packages. Since a patch is available, applying the update is the recommended mitigation. No additional mitigations or workarounds are specified by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:17611
Cve Count
3
Additional Cves
["CVE-2026-30922","CVE-2026-40192"]

Threat ID: 6a160980e29bf47b5064d84c

Added to database: 05/26/2026, 20:58:40 UTC

Last enriched: 08/17/2026, 19:21:29 UTC

Last updated: 09/12/2026, 22:01:32 UTC

Views: 95

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:24483https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.4/html-single/release_notes/indexhttps://access.redhat.com/security/cve/CVE-2026-23490https://access.redhat.com/security/cve/CVE-2026-39892https://access.redhat.com/security/cve/CVE-2026-44431https://access.redhat.com/security/cve/CVE-2026-44432https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:24476https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3https://access.redhat.com/documentation/en-us/red_hat_trusted_artifact_signer/1.3/html-single/release_notes/indexCanonical URLhttps://access.redhat.com/errata/RHSA-2026:17611https://access.redhat.com/security/cve/CVE-2026-30922https://access.redhat.com/security/cve/CVE-2026-40192https://www.redhat.com/en/technologies/linux-platforms/enterprise-linux/aiCanonical URLhttps://access.redhat.com/errata/RHSA-2026:1903https://access.redhat.com/security/updates/classification/#important2430472Canonical URLhttps://access.redhat.com/errata/RHSA-2026:3359Canonical URLhttps://access.redhat.com/errata/RHSA-2026:3354Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1904Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1905Canonical URLhttps://access.redhat.com/errata/RHSA-2026:1906Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2221Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2299Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2300Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2302Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2303Canonical URLSearch on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses