From 24b54bef7c89d9538ef1a07ee437028fd1eb285f Mon Sep 17 00:00:00 2001 From: Oyvind Albrigtsen Date: Tue, 6 Jan 2026 09:54:09 +0100 Subject: [PATCH] - bundled urllib3: fix CVE-2025-66418 Resolves: RHEL-136027 --- ...7-fix-bundled-urllib3-CVE-2025-66418.patch | 68 +++++++++++++++++++ fence-agents.spec | 8 ++- 2 files changed, 75 insertions(+), 1 deletion(-) create mode 100644 RHEL-136027-fix-bundled-urllib3-CVE-2025-66418.patch diff --git a/RHEL-136027-fix-bundled-urllib3-CVE-2025-66418.patch b/RHEL-136027-fix-bundled-urllib3-CVE-2025-66418.patch new file mode 100644 index 0000000..4915086 --- /dev/null +++ b/RHEL-136027-fix-bundled-urllib3-CVE-2025-66418.patch @@ -0,0 +1,68 @@ +--- a/aws/urllib3/response.py 2023-10-17 19:42:56.000000000 +0200 ++++ b/aws/urllib3/response.py 2026-01-02 11:19:25.583808492 +0100 +@@ -135,8 +135,18 @@ + they were applied. + """ + ++ # Maximum allowed number of chained HTTP encodings in the ++ # Content-Encoding header. ++ max_decode_links = 5 ++ + def __init__(self, modes): +- self._decoders = [_get_decoder(m.strip()) for m in modes.split(",")] ++ encodings = [m.strip() for m in modes.split(",")] ++ if len(encodings) > self.max_decode_links: ++ raise DecodeError( ++ "Too many content encodings in the chain: " ++ f"{len(encodings)} > {self.max_decode_links}" ++ ) ++ self._decoders = [_get_decoder(e) for e in encodings] + + def flush(self): + return self._decoders[0].flush() + +--- a/azure/urllib3/response.py 2023-10-17 19:42:56.000000000 +0200 ++++ b/azure/urllib3/response.py 2026-01-02 11:19:25.583808492 +0100 +@@ -135,8 +135,18 @@ + they were applied. + """ + ++ # Maximum allowed number of chained HTTP encodings in the ++ # Content-Encoding header. ++ max_decode_links = 5 ++ + def __init__(self, modes): +- self._decoders = [_get_decoder(m.strip()) for m in modes.split(",")] ++ encodings = [m.strip() for m in modes.split(",")] ++ if len(encodings) > self.max_decode_links: ++ raise DecodeError( ++ "Too many content encodings in the chain: " ++ f"{len(encodings)} > {self.max_decode_links}" ++ ) ++ self._decoders = [_get_decoder(e) for e in encodings] + + def flush(self): + return self._decoders[0].flush() + +--- a/kubevirt/urllib3/response.py 2023-10-17 19:42:56.000000000 +0200 ++++ b/kubevirt/urllib3/response.py 2026-01-02 11:19:25.583808492 +0100 +@@ -135,8 +135,18 @@ + they were applied. + """ + ++ # Maximum allowed number of chained HTTP encodings in the ++ # Content-Encoding header. ++ max_decode_links = 5 ++ + def __init__(self, modes): +- self._decoders = [_get_decoder(m.strip()) for m in modes.split(",")] ++ encodings = [m.strip() for m in modes.split(",")] ++ if len(encodings) > self.max_decode_links: ++ raise DecodeError( ++ "Too many content encodings in the chain: " ++ f"{len(encodings)} > {self.max_decode_links}" ++ ) ++ self._decoders = [_get_decoder(e) for e in encodings] + + def flush(self): + return self._decoders[0].flush() diff --git a/fence-agents.spec b/fence-agents.spec index c4ddd14..f3097e0 100644 --- a/fence-agents.spec +++ b/fence-agents.spec @@ -87,7 +87,7 @@ Name: fence-agents Summary: Set of unified programs capable of host isolation ("fencing") Version: 4.2.1 -Release: 129%{?alphatag:.%{alphatag}}%{?dist}.16 +Release: 129%{?alphatag:.%{alphatag}}%{?dist}.17 License: GPLv2+ and LGPLv2+ Group: System Environment/Base URL: https://github.com/ClusterLabs/fence-agents @@ -336,6 +336,7 @@ Patch2000: bz2218234-2-aws-fix-bundled-dateutil-CVE-2007-4559.patch Patch2001: RHEL-43568-2-aws-fix-bundled-urllib3-CVE-2024-37891.patch Patch2002: RHEL-104741-2-aliyun-aws-azure-fix-bundled-requests-CVE-2024-47081.patch Patch2003: RHEL-109814-2-botocore-add-SkipOsShutdown.patch +Patch2004: RHEL-136027-fix-bundled-urllib3-CVE-2025-66418.patch %if 0%{?fedora} || 0%{?rhel} > 7 %global supportedagents amt_ws apc apc_snmp bladecenter brocade cisco_mds cisco_ucs compute drac5 eaton_snmp emerson eps evacuate hds_cb hpblade ibmblade ibm_powervs ibm_vpc ifmib ilo ilo_moonshot ilo_mp ilo_ssh intelmodular ipdu ipmilan kdump kubevirt lpar mpath nutanix_ahv redfish rhevm rsa rsb sbd scsi vmware_rest vmware_soap wti @@ -695,6 +696,7 @@ pushd %{buildroot}/usr/lib/fence-agents/%{bundled_lib_dir} /usr/bin/patch --no-backup-if-mismatch -p1 --fuzz=2 < %{PATCH2001} /usr/bin/patch --no-backup-if-mismatch -p1 --fuzz=2 < %{PATCH2002} /usr/bin/patch --no-backup-if-mismatch -p1 --fuzz=0 < %{PATCH2003} +/usr/bin/patch --no-backup-if-mismatch -p1 --fuzz=0 < %{PATCH2004} %endif popd @@ -1628,6 +1630,10 @@ Fence agent for IBM z/VM over IP. %endif %changelog +* Tue Jan 6 2026 Oyvind Albrigtsen - 4.2.1-129.17 +- bundled urllib3: fix CVE-2025-66418 + Resolves: RHEL-136027 + * Mon Nov 3 2025 Oyvind Albrigtsen - 4.2.1-129.16 - fence_nutanix_ahv: new fence agent Resolves: RHEL-110964