Logo
vulnerabilityCVE-2026-35091
Name
CVE-2026-35091
Source
NVD ( link)Debian ( link)
Description
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
corosync
Patched

Vulnerability Ratings#


8.2
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
kirkstone
3.0.3
Not Affected
yocto
master
3.1.10
Patched

Resolved with patches#


corosync (yocto:master)

#
Title
Author
Resolve
1
totemsrp: Return error if sanity check fails
Jan Friesse <jfriesse@redhat.com>
CVE-2026-35091

corosync (yocto:scarthgap)

#
Title
Author
Resolve
1
totemsrp: Return error if sanity check fails
Jan Friesse <jfriesse@redhat.com>
CVE-2026-35091