yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2025-30472
Component Overview
Vulnerability Overview
Name
CVE-2025-30472
Source
NVD (
link
)
Debian (
link
)
Description
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.
CWEs
CWE-121
CWE-787
Published Date
Mar 22, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://corosync.org
Product
https://github.com/corosync/corosync/blob/73ba225cc48ebb1903897c792065cb5e876613b0/exec/totemsrp.c#L4677
Product
https://github.com/corosync/corosync/issues/778
Exploit
https://github.com/corosync/corosync/issues/778
Exploit
Analysis
#
Affected Component
Analysis
corosync
Patched
Vulnerability Ratings
#
9
CVSSv31
9.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
corosync
yocto
master
3.1.10
Not Affected
corosync
yocto
scarthgap
3.1.10
Not Affected
Resolved with patches
#
corosync (yocto:kirkstone)
#
Title
Author
Resolve
1
totemsrp: Check size of orf_token msg
Jan Friesse <jfriesse@redhat.com>
CVE-2025-30472