Your message dated Mon, 14 Sep 2026 21:26:32 +0000
with message-id <[email protected]>
and subject line Bug#1147515: fixed in pcs 0.12.3.1-1
has caused the Debian Bug report #1147515,
regarding pcs: CVE-2026-84828
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1147515: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147515
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: pcs
Version: 0.10.8-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for pcs.
Unfortunately according to the Red Hat bug, the commit referenced is
not yet public?
CVE-2026-84828[0]:
| A flaw was found in PCS (Pacemaker Configuration System). A local
| attacker with membership in the 'haclient' group can exploit the
| 'pcs host auth --token' command to read the contents of arbitrary
| files on the filesystem, provided the files are shorter than 256
| bytes. The file contents are read with root privileges by the pcsd
| daemon and can be exfiltrated by the attacker through subsequent
| cluster node communication. This allows disclosure of sensitive data
| such as API keys, tokens, or configuration secrets that would
| otherwise be inaccessible to the attacker.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-84828
https://www.cve.org/CVERecord?id=CVE-2026-84828
[1] https://bugzilla.redhat.com/show_bug.cgi?id=2527320
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: pcs
Source-Version: 0.12.3.1-1
Done: Valentin Vidic <[email protected]>
We believe that the bug you reported is fixed in the latest version of
pcs, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Valentin Vidic <[email protected]> (supplier of updated pcs package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 14 Sep 2026 22:33:17 +0200
Source: pcs
Architecture: source
Version: 0.12.3.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian HA Maintainers
<[email protected]>
Changed-By: Valentin Vidic <[email protected]>
Closes: 1147515
Changes:
pcs (0.12.3.1-1) unstable; urgency=medium
.
* New upstream version 0.12.3.1 fixing:
- CVE-2026-84828: Disclosure of sensitive data (Closes: #1147515)
* d/patches: fix build with json gem v3
Checksums-Sha1:
8d2644a57613de53ef685cb2b87515f728d98a2b 2617 pcs_0.12.3.1-1.dsc
19dd1f1f774152c78917157b9b4969b600307745 1879532 pcs_0.12.3.1.orig.tar.gz
94c26b68db4d89e7703781ae5c006ed9c6cb8294 10996 pcs_0.12.3.1-1.debian.tar.xz
ef5d86dd46efe87063b89b16713d31b1e1792cc4 9173 pcs_0.12.3.1-1_source.buildinfo
Checksums-Sha256:
a2156626975cb72af63ead866a339913d90e26369617444d7428a41944a343d9 2617
pcs_0.12.3.1-1.dsc
eb5a80eaea1dc46ef9d9b675a79219704edc9ae071056ce6d67bbfea975f951d 1879532
pcs_0.12.3.1.orig.tar.gz
ce8a3375965fb31feff64433cbebb9f483b89e066f47f883ce313c89126adc74 10996
pcs_0.12.3.1-1.debian.tar.xz
c2909735267ba564905fc57390f4cb28ebbaa267af4e6d9e56466e357c336220 9173
pcs_0.12.3.1-1_source.buildinfo
Files:
8cd55bb4dc5f5f65fbae22e5b616763a 2617 admin optional pcs_0.12.3.1-1.dsc
7a8fc5c48b250b3558b431cbe2f48ec3 1879532 admin optional
pcs_0.12.3.1.orig.tar.gz
043c1be87068df878f0979f6f6198d22 10996 admin optional
pcs_0.12.3.1-1.debian.tar.xz
84b7d78b673c1d0465aa3033a8389da7 9173 admin optional
pcs_0.12.3.1-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEExaW53cM9k/u2PWfIMofYmpfNqHsFAmqoY/oSHHZ2aWRpY0Bk
ZWJpYW4ub3JnAAoJEDKH2JqXzah7i9YP/jHK6+oS/GXuRcwsiVMcJ7qv2ddjHKQH
gbMGXQ4t5rtXNqtYerfP/UbSWS6QtAXao6p1u54oKmCb64wpHaYfNpT6h7o8wHRE
lV1GptQHpGngLQnv5fJ6neAMiqwM8YItoWI/z4mvdHom7Vifys09nl07HqQcPhTi
SkAPW37zvJ7A/puVpIP3kCty+A+O5OwYjHXm8q4L/OaaaWIEum8YNnoCyO05F+hj
1QMct6vKEyZVcehciCJi5mfjPSm0MOUUEqJXKisPPr3EZKDOvDhjKpvW8csEaDAF
fkVGNl/iuiWXcxHuW5PrvYhCZGzMP7dk5LPiWlizpMXtbZvfGzt1GnfEAG30Kttr
pkomJItlJ9GYpFh8PD196IbgNLQI5CrdM8fsPGHsXxDB2rssmMHUAZwbypjNAxiq
N+ExyTzdC+ofnGP2XIxCUSi3vTrPH4fNVzI0t/plBs+cLCmMt86lrP3/AGmaKSI4
RUi+kwUv+4JakOsJjrAB7981VGWVuXWaznzXovMYf644JVWuXDpqgo8doiZ72EIo
hj6RxedvDHMbGNoinzQfQjl6LMxea5giGtkRl6N/EtJxQsJNV6PosgBeO/C9yv53
XMPuTuZr5StZsuw6mGBkwe0+8GI380aSehA3s5QsG8YcvzTvf34jFJzbTIDbyn9j
xIjYGYK28+zg
=vDI7
-----END PGP SIGNATURE-----
pgp5YOW2VpGPS.pgp
Description: PGP signature
--- End Message ---