Red Hat Security Advisory: fence-agents security update
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID (CVE-2026-23490) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
CVE-2026-23490 is a vulnerability in the pyasn1 Python library, which is used by Red Hat fence-agents packages for remote power management in cluster environments. The vulnerability is triggered by a malformed RELATIVE-OID containing excessive continuation octets, causing uncontrolled memory allocation and exhaustion. This results in a denial of service condition by consuming excessive system resources. The issue is classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and related CWEs involving resource consumption. Red Hat has acknowledged the vulnerability and provided patches to mitigate the risk.
Potential Impact
An attacker can cause a denial of service by sending specially crafted input that triggers excessive memory allocation in the pyasn1 library. This leads to resource exhaustion, potentially making the affected system or cluster node unresponsive or unavailable. There is no impact on confidentiality or integrity reported. The severity is rated high by Red Hat due to the availability impact.
Mitigation Recommendations
Red Hat has released patches that fix this vulnerability. Users should apply the official updates provided by Red Hat to the pyasn1 library and fence-agents packages. Since a patch is available, applying the update is the recommended mitigation. No additional mitigations or workarounds are specified by the vendor advisory.
Red Hat Security Advisory: fence-agents security update
Description
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID (CVE-2026-23490) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-23490 is a vulnerability in the pyasn1 Python library, which is used by Red Hat fence-agents packages for remote power management in cluster environments. The vulnerability is triggered by a malformed RELATIVE-OID containing excessive continuation octets, causing uncontrolled memory allocation and exhaustion. This results in a denial of service condition by consuming excessive system resources. The issue is classified under CWE-770 (Allocation of Resources Without Limits or Throttling) and related CWEs involving resource consumption. Red Hat has acknowledged the vulnerability and provided patches to mitigate the risk.
Potential Impact
An attacker can cause a denial of service by sending specially crafted input that triggers excessive memory allocation in the pyasn1 library. This leads to resource exhaustion, potentially making the affected system or cluster node unresponsive or unavailable. There is no impact on confidentiality or integrity reported. The severity is rated high by Red Hat due to the availability impact.
Mitigation Recommendations
Red Hat has released patches that fix this vulnerability. Users should apply the official updates provided by Red Hat to the pyasn1 library and fence-agents packages. Since a patch is available, applying the update is the recommended mitigation. No additional mitigations or workarounds are specified by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:17611
- Cve Count
- 3
- Additional Cves
- ["CVE-2026-30922","CVE-2026-40192"]
Threat ID: 6a160980e29bf47b5064d84c
Added to database: 05/26/2026, 20:58:40 UTC
Last enriched: 08/17/2026, 19:21:29 UTC
Last updated: 09/12/2026, 22:01:32 UTC
Views: 95
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.