Logo
componentcorosync
Name
corosync
Version
3.1.10
Type
library
Description
The Corosync Cluster Engine and Application Programming Interfaces
Licenses
BSD-3-Clause
PURL
-
CPE
cpe:2.3:*:*:corosync:3.1.10:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
3.0.3
master
3.1.10

Patches#


#
Title
Author
Resolve
1
totemsrp: Fix integer overflow in memb_join_sanity
Jan Friesse <jfriesse@redhat.com>
CVE-2026-35092
2
totemsrp: Return error if sanity check fails
Jan Friesse <jfriesse@redhat.com>
CVE-2026-35091

Vulnerabilities#


Name
Analysis
Description
Patched
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.
Patched
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents