Hi, The following vulnerability was published for pcs. Unfortunately according to the Red Hat bug, the commit referenced is not yet public? CVE-2026-84828[0]: | A flaw was found in PCS (Pacemaker Configuration System). A local | attacker with membership in the 'haclient' group can exploit the | 'pcs host auth --token' command to read the contents of arbitrary | files on the filesystem, provided the files are shorter than 256 | bytes. The file contents are read with root privileges by the pcsd | daemon and can be exfiltrated by the attacker through subsequent | cluster node communication. This allows disclosure of sensitive data | such as API keys, tokens, or configuration secrets that would | otherwise be inaccessible to the attacker. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-84828 https://www.cve.org/CVERecord?id=CVE-2026-84828 [1] https://bugzilla.redhat.com/show_bug.cgi?id=2527320 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
pcs, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1147515@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Valentin Vidic <vvidic@debian.org> (supplier of updated pcs package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 14 Sep 2026 22:33:17 +0200
Source: pcs
Architecture: source
Version: 0.12.3.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org>
Changed-By: Valentin Vidic <vvidic@debian.org>
Closes: 1147515
Changes:
pcs (0.12.3.1-1) unstable; urgency=medium
.
* New upstream version 0.12.3.1 fixing:
- CVE-2026-84828: Disclosure of sensitive data (Closes: #1147515)
* d/patches: fix build with json gem v3
Checksums-Sha1:
8d2644a57613de53ef685cb2b87515f728d98a2b 2617 pcs_0.12.3.1-1.dsc
19dd1f1f774152c78917157b9b4969b600307745 1879532 pcs_0.12.3.1.orig.tar.gz
94c26b68db4d89e7703781ae5c006ed9c6cb8294 10996 pcs_0.12.3.1-1.debian.tar.xz
ef5d86dd46efe87063b89b16713d31b1e1792cc4 9173 pcs_0.12.3.1-1_source.buildinfo
Checksums-Sha256:
a2156626975cb72af63ead866a339913d90e26369617444d7428a41944a343d9 2617 pcs_0.12.3.1-1.dsc
eb5a80eaea1dc46ef9d9b675a79219704edc9ae071056ce6d67bbfea975f951d 1879532 pcs_0.12.3.1.orig.tar.gz
ce8a3375965fb31feff64433cbebb9f483b89e066f47f883ce313c89126adc74 10996 pcs_0.12.3.1-1.debian.tar.xz
c2909735267ba564905fc57390f4cb28ebbaa267af4e6d9e56466e357c336220 9173 pcs_0.12.3.1-1_source.buildinfo
Files:
8cd55bb4dc5f5f65fbae22e5b616763a 2617 admin optional pcs_0.12.3.1-1.dsc
7a8fc5c48b250b3558b431cbe2f48ec3 1879532 admin optional pcs_0.12.3.1.orig.tar.gz
043c1be87068df878f0979f6f6198d22 10996 admin optional pcs_0.12.3.1-1.debian.tar.xz
84b7d78b673c1d0465aa3033a8389da7 9173 admin optional pcs_0.12.3.1-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEExaW53cM9k/u2PWfIMofYmpfNqHsFAmqoY/oSHHZ2aWRpY0Bk
ZWJpYW4ub3JnAAoJEDKH2JqXzah7i9YP/jHK6+oS/GXuRcwsiVMcJ7qv2ddjHKQH
gbMGXQ4t5rtXNqtYerfP/UbSWS6QtAXao6p1u54oKmCb64wpHaYfNpT6h7o8wHRE
lV1GptQHpGngLQnv5fJ6neAMiqwM8YItoWI/z4mvdHom7Vifys09nl07HqQcPhTi
SkAPW37zvJ7A/puVpIP3kCty+A+O5OwYjHXm8q4L/OaaaWIEum8YNnoCyO05F+hj
1QMct6vKEyZVcehciCJi5mfjPSm0MOUUEqJXKisPPr3EZKDOvDhjKpvW8csEaDAF
fkVGNl/iuiWXcxHuW5PrvYhCZGzMP7dk5LPiWlizpMXtbZvfGzt1GnfEAG30Kttr
pkomJItlJ9GYpFh8PD196IbgNLQI5CrdM8fsPGHsXxDB2rssmMHUAZwbypjNAxiq
N+ExyTzdC+ofnGP2XIxCUSi3vTrPH4fNVzI0t/plBs+cLCmMt86lrP3/AGmaKSI4
RUi+kwUv+4JakOsJjrAB7981VGWVuXWaznzXovMYf644JVWuXDpqgo8doiZ72EIo
hj6RxedvDHMbGNoinzQfQjl6LMxea5giGtkRl6N/EtJxQsJNV6PosgBeO/C9yv53
XMPuTuZr5StZsuw6mGBkwe0+8GI380aSehA3s5QsG8YcvzTvf34jFJzbTIDbyn9j
xIjYGYK28+zg
=vDI7
-----END PGP SIGNATURE-----