A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade corosync-debuginfoUpgrade corosynclibUpgrade corosync-debugsourceUpgrade corosync-vqsim-debuginfoUpgrade corosynclib-develUpgrade corosync-vqsimUpgrade corosyncUpgrade corosynclib-debuginfo | Sep 30, 2026 | Sep 4, 2026 |
| Redhat_linux | — | Upgrade corosynclib-develUpgrade corosynclibUpgrade corosync-vqsimUpgrade corosync-debugsourceUpgrade spauseddUpgrade corosynclib-debuginfoUpgrade spausedd-debuginfoUpgrade corosync-qnetdUpgrade corosync-vqsim-debuginfoUpgrade corosyncUpgrade corosync-debuginfoUpgrade corosync-qdevice | Sep 7, 2026 | Sep 4, 2026 |
| Rocky_linux | — | Upgrade corosyncUpgrade corosynclib-debuginfoUpgrade spauseddUpgrade corosync-vqsim-debuginfoUpgrade corosynclibUpgrade corosync-debugsourceUpgrade corosynclib-develUpgrade corosync-vqsimUpgrade corosync-debuginfoUpgrade spausedd-debuginfo | Sep 18, 2026 | Sep 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub