A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade corosynclib-debuginfoUpgrade spauseddUpgrade corosync-vqsimUpgrade corosynclib-develUpgrade corosync-debugsourceUpgrade corosynclibUpgrade spausedd-debuginfoUpgrade corosync-qdeviceUpgrade corosync-debuginfoUpgrade corosyncUpgrade corosync-vqsim-debuginfoUpgrade corosync-qnetd | Sep 7, 2026 | Sep 4, 2026 |
| Rocky_linux | — | Upgrade corosynclib-develUpgrade corosynclibUpgrade corosync-debugsourceUpgrade corosync-vqsimUpgrade corosync-debuginfoUpgrade corosynclib-debuginfoUpgrade corosync-vqsim-debuginfoUpgrade corosync | Sep 18, 2026 | Sep 17, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub