FlawAtlas
Search the atlas
ALSA-2025:0308 Not scored

Important: fence-agents security update

The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * fence-agents: Jinja has a sandbox breakout through indirect reference to format method [almalinux-9.5.z] (CVE-2024-56326) * fence-agents: Jinja has a sandbox breakout through malicious filenames [almalinux-9.5.z] (CVE-2024-56201)

Exploit probability Not scored
Published January 14, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

AlmaLinux:9 fence-agents-common
AlmaLinux:9 fence-agents-compute
AlmaLinux:9 fence-agents-ibm-powervs
AlmaLinux:9 fence-agents-ibm-vpc
AlmaLinux:9 fence-agents-kubevirt
AlmaLinux:9 fence-agents-virsh
AlmaLinux:9 fence-virt
AlmaLinux:9 fence-virtd
AlmaLinux:9 fence-virtd-cpg
AlmaLinux:9 fence-virtd-libvirt
AlmaLinux:9 fence-virtd-multicast
AlmaLinux:9 fence-virtd-serial
AlmaLinux:9 fence-virtd-tcp

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities ALSA-2025:0308

The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): * fence-agents: Jinja has a sandbox breakout through indirect reference to format method [almalinux-9.5.z] (CVE-2024-56326) * fence-agents: Jinja has a sandbox breakout through malicious filenames [almalinux-9.5.z] (CVE-2024-56201)

View original source

05 / REFERENCES

Further evidence