Home

Description

A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents

PUBLISHED Reserved 2026-04-01 | Published 2026-04-01 | Updated 2026-05-29 | Assigner redhat




HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Problem types

Incorrect Check of Function Return Value

Product status

Default status
affected

0:3.1.9-2.el10_1.1 (rpm) before *
unaffected

Default status
affected

0:3.1.10-1.el10_2.1 (rpm) before *
unaffected

Default status
affected

0:3.1.9-1.el10_0.2 (rpm) before *
unaffected

Default status
affected

0:2.4.5-7.el7_9.3 (rpm) before *
unaffected

Default status
affected

0:3.1.8-1.el8_10.1 (rpm) before *
unaffected

Default status
affected

0:3.1.0-3.el8_4.2 (rpm) before *
unaffected

Default status
affected

0:3.1.0-3.el8_4.2 (rpm) before *
unaffected

Default status
affected

0:3.1.5-2.el8_6.1 (rpm) before *
unaffected

Default status
affected

0:3.1.5-2.el8_6.1 (rpm) before *
unaffected

Default status
affected

0:3.1.5-2.el8_6.1 (rpm) before *
unaffected

Default status
affected

0:3.1.7-1.el8_8.1 (rpm) before *
unaffected

Default status
affected

0:3.1.7-1.el8_8.1 (rpm) before *
unaffected

Default status
affected

0:3.1.9-2.el9_7.1 (rpm) before *
unaffected

Default status
affected

0:3.1.10-1.el9_8.1 (rpm) before *
unaffected

Default status
affected

0:3.1.5-3.el9_0.1 (rpm) before *
unaffected

Default status
affected

0:3.1.7-1.el9_2.1 (rpm) before *
unaffected

Default status
affected

0:3.1.8-1.el9_4.1 (rpm) before *
unaffected

Default status
affected

0:3.1.9-2.el9_6.1 (rpm) before *
unaffected

Default status
unaffected

Timeline

2026-04-01:Reported to Red Hat.
2026-04-01:Made public.

Credits

Red Hat would like to thank Sebastián Alba Vives for reporting this issue.

References

access.redhat.com/errata/RHSA-2026:13644 (RHSA-2026:13644) vendor-advisory

access.redhat.com/errata/RHSA-2026:13657 (RHSA-2026:13657) vendor-advisory

access.redhat.com/errata/RHSA-2026:13673 (RHSA-2026:13673) vendor-advisory

access.redhat.com/errata/RHSA-2026:14205 (RHSA-2026:14205) vendor-advisory

access.redhat.com/errata/RHSA-2026:14210 (RHSA-2026:14210) vendor-advisory

access.redhat.com/errata/RHSA-2026:14211 (RHSA-2026:14211) vendor-advisory

access.redhat.com/errata/RHSA-2026:14212 (RHSA-2026:14212) vendor-advisory

access.redhat.com/errata/RHSA-2026:14213 (RHSA-2026:14213) vendor-advisory

access.redhat.com/errata/RHSA-2026:14214 (RHSA-2026:14214) vendor-advisory

access.redhat.com/errata/RHSA-2026:14215 (RHSA-2026:14215) vendor-advisory

access.redhat.com/errata/RHSA-2026:14216 (RHSA-2026:14216) vendor-advisory

access.redhat.com/errata/RHSA-2026:19043 (RHSA-2026:19043) vendor-advisory

access.redhat.com/errata/RHSA-2026:19200 (RHSA-2026:19200) vendor-advisory

access.redhat.com/errata/RHSA-2026:20916 (RHSA-2026:20916) vendor-advisory

access.redhat.com/security/cve/CVE-2026-35091 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2453169

bugzilla.redhat.com/show_bug.cgi?id=2453813 (RHBZ#2453813) issue-tracking

cve.org (CVE-2026-35091)

nvd.nist.gov (CVE-2026-35091)

Download JSON