Pacemaker
High-availability cluster resource manager for Linux
Pacemaker is putting TLS and X509 auth between its cluster nodes, then hardening the wire code.
◆Recent moves
- 11d ago
3.0.3: CVE-2026-10649 and remote message overflow fixes
A 20-commit security release fixing CVE-2026-10649, two integer overflows in remote message handling, and a cap on remote message size, plus repairs to the ClusterMon regression from 3.0.2. Small in volume, consequential for anyone running Pacemaker Remote.
View source ↗ - 28d ago
3.0.2: PSK auth for remote CIB operations
The bulk release of the 3.0 line at 1856 commits, adding PSK authentication for remote CIB operations, an allow_fencing_disabled parameter, and fencer improvements. It also ships with three documented regressions, all fixed in 3.0.3.
View source ↗ - 28d ago
3.0.1: TLS and X509 authentication for Pacemaker Remote
⚡ SPARKThe release where cluster communication stops assuming a trusted network: TLS for Pacemaker Remote nodes, X509 authentication, and TLS certificates for remote CIB operations, on top of large IPC and multipart message support. Everything since, the PSK work in 3.0.2 and the overflow fixes in 3.0.3, is built on this change.
View source ↗ - 28d ago
3.0.3-rc1: release candidate for the CVE fix set
The release candidate for 3.0.3, with an identical commit count, file count, and fix list to the final tag published two weeks later. It is the same fix set under review, not separate work.
View source ↗ - 1mo ago
2.1.11: CVE-2026-10649 backported to the maintenance branch
The same CVE-2026-10649 fix and remote message overflow guards backported to the 2.1 maintenance branch, plus strftime build checks. It is the older branch receiving the security train rather than new capability.
View source ↗ - 1mo ago
2.1.11-rc1: release candidate for the 2.1 CVE backport
Release candidate for 2.1.11 with the same 18 commits and 27 files as the final tag a week later. A staging tag, not distinct content.
View source ↗