Instructions for LKWMC Package Installation ---------------------------------------------------------- Issue(s) addressed by this patch (PL-34853): This patch addresses GO-2026-5026 (CVE-2026-39821), a vulnerability in the Go standard library used to build the LifeKeeper Web Management Console (LKWMC) component. This fix rebuilds the LKWMC package against Go 1.27.1 (latest stable release), which resolves the vulnerability. ------------------------- Patch Description: This patch provides an updated steeleye-lkWMC rpm rebuilt with Go 1.27.1 in place of the previously used Go version. No functional or behavioral changes are introduced by this patch; it is a security-only rebuild. ------------------------- AFFECTED ENVIRONMENTS: * Operating system * All Linux distributions supported by LifeKeeper (RHEL, SLES, Oracle Linux, Rocky Linux, Miracle Linux, AlmaLinux, and other supported derivatives) * Application Recovery Kit / Component * LKWMC (LifeKeeper Web Management Console) This patch is not kernel-version dependent and is not tied to a specific distro minor release. It is built specifically for LifeKeeper 10.1.0 with steeleye-lkWMC-10.1.0-867 installed. Note: This patch does not apply to systems where the LKWMC is not installed, where a different LifeKeeper core version is installed, or with a different steeleye-lkWMC version. ------------------------- Affected Package / Fixed Package: Affected: steeleye-lkWMC-10.1.0-867.x86_64.rpm Fixed: steeleye-lkWMC-10.1.0-868.x86_64.rpm ------------------------- Patch Installation This patch is distributed as a standalone rpm and is installed as an in-place upgrade of the existing LKWMC package. LifeKeeper does not need to be stopped to apply this patch. 1) Download the patch This patch can be found on the SIOS downloads site at the following location: https://downloads.us.sios.com/Linux/LifeKeeper_for_Linux/10.1.0/patches/HOTFIX-PL-34853-LKWMC_GO_CVE-2026-39821 To download the patch and associated files on Linux perform the following steps: # wget https://downloads.us.sios.com/Linux/LifeKeeper_for_Linux/10.1.0/patches/HOTFIX-PL-34853-LKWMC_GO_CVE-2026-39821/steeleye-lkWMC-10.1.0-868.x86_64.rpm # wget https://downloads.us.sios.com/Linux/LifeKeeper_for_Linux/10.1.0/patches/HOTFIX-PL-34853-LKWMC_GO_CVE-2026-39821/steeleye-lkWMC-10.1.0-868.x86_64.rpm.sha256sum # wget https://downloads.us.sios.com/Linux/LifeKeeper_for_Linux/10.1.0/patches/patches/HOTFIX-PL-34853-LKWMC_GO_CVE-2026-39821/readme.txt 2) Verify the download Verify the checksum by running the following command: # sha256sum -c steeleye-lkWMC-10.1.0-868.x86_64.rpm.sha256sum NOTE: Alternative download methods can be used but must include all files. Once the download is complete, a verification of the sha256sum should be performed before installing. 3) Install the patch a. Determine whether steeleye-lkWMC is installed Check the installed version by running: # rpm -q steeleye-lkWMC If steeleye-lkWMC-10.1.0-867 is installed, go to step 3b. If steeleye-lkWMC is not installed, go to step 3c. If a different version is installed, this patch does not apply to your system. b. Upgrading an existing installation Place the steeleye-lkWMC-10.1.0-868.x86_64.rpm file anywhere on the server where LKWMC is installed. In this document, it is assumed to be placed under /root. For other locations, change the path name accordingly. Upgrade the existing package in place using the following command: # rpm -U /root/steeleye-lkWMC-10.1.0-868.x86_64.rpm No LifeKeeper service restart or resource switchover is required to apply this patch, as LKWMC is a management console component and is independent of protected resource operation. However, any active browser sessions connected to the WMC should be refreshed after the upgrade to pick up the updated console. After the upgrade is complete, the downloaded temporary files can be removed: # rm -f /root/steeleye-lkWMC-10.1.0-868.x86_64.rpm # rm -f /root/steeleye-lkWMC-10.1.0-868.x86_64.rpm.sha256sum # rm -f /root/readme.txt Perform the steps in 'Verifying the LKWMC package installation' to ensure that the updated package has been installed correctly. c. Fresh installation On a system where LKWMC is not yet installed, install steeleye-lkWMC-10.1.0-868.x86_64.rpm directly: # rpm -i /root/steeleye-lkWMC-10.1.0-868.x86_64.rpm ------------------------- Verifying the LKWMC package installation Verify the updated package has been installed by running: # rpm -q steeleye-lkWMC The output should include: steeleye-lkWMC-10.1.0-868.x86_64 ------------------------- Uninstalling the patch / Rolling back To roll back to the previous package version if required first uninstall the steeleye-lkWMC package and then re-run the LifeKeeper installer. You do not need to uninstall this patch prior to upgrading LifeKeeper. # rpm -e steeleye-lkWMC-10.1.0-868.x86_64 Note: Rolling back reintroduces the vulnerability addressed by this patch (CVE-2026-39821 / GO-2026-5026) and is not recommended except for troubleshooting purposes.