Logo
componentcorosync
Name
corosync
Version
3.0.3
Type
library
Description
The Corosync Cluster Engine and Application Programming Interfaces
Licenses
BSD-3-Clause
PURL
-
CPE
cpe:2.3:*:*:corosync:3.0.3:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
3.1.10
scarthgap
3.1.10

Patches#


#
Title
Author
Resolve
1
totemsrp: Check size of orf_token msg
Jan Friesse <jfriesse@redhat.com>
CVE-2025-30472

Vulnerabilities#


Name
Analysis
Description
Patched
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.