VDB
ALSA-2025%3A0308
ALSA-2025%3A0308
PUBLISHED
The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * fence-agents: Jinja has a sandbox breakout through indirect reference to format method [almalinux-9.5.z] (CVE-2024-56326) * fence-agents: Jinja has a sandbox breakout through malicious filenames [almalinux-9.5.z] (CVE-2024-56201)
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AlmaLinux:9 | fence-virtd-libvirt | 0, 0 |
| AlmaLinux:9 | fence-virtd | 0, 0 |
| AlmaLinux:9 | fence-virtd-cpg | 0, 0 |
| AlmaLinux:9 | fence-virtd-serial | 0, 0 |
| AlmaLinux:9 | fence-agents-common | 0, 0 |
| AlmaLinux:9 | fence-agents-ibm-vpc | 0, 0 |
| AlmaLinux:9 | fence-agents-virsh | 0, 0 |
| AlmaLinux:9 | fence-agents-compute | 0, 0 |
| AlmaLinux:9 | fence-virtd-tcp | 0, 0 |
| AlmaLinux:9 | fence-agents-kubevirt | 0, 0 |
| AlmaLinux:9 | fence-virtd-multicast | 0, 0 |
| AlmaLinux:9 | fence-virt | 0, 0 |
| AlmaLinux:9 | fence-agents-ibm-powervs | 0, 0 |
Timeline
- Jan 14, 2025 CVE Published
- Jan 15, 2025 CVE Updated
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:0308 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2024-56201 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2024-56326 third-party-advisory
- https://errata.almalinux.org/9/ALSA-2025-0308.html vendor-advisory