Description
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- Corosync / Corosync
- RedHat / enterprise_linux7.0 – 7.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / openshift4.0 – 4.0
References
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:13644
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:13657
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:13673
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:14205
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:14210
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:14211
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:14212
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:14213
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:14214
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:14215
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:14216
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:19043
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:19200
- VENDOR_ADVISORYhttps://access.redhat.com/errata/RHSA-2026:20916
- VENDOR_ADVISORYhttps://access.redhat.com/security/cve/CVE-2026-35092
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2453169
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=2453814
Updated 17m ago · 8 sources