Description
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.
Problem types
Integer Overflow or Wraparound
Product status
0:3.1.9-2.el10_1.1 (rpm) before *
0:3.1.10-1.el10_2.1 (rpm) before *
0:3.1.9-1.el10_0.2 (rpm) before *
0:2.4.5-7.el7_9.3 (rpm) before *
0:3.1.8-1.el8_10.1 (rpm) before *
0:3.1.0-3.el8_4.2 (rpm) before *
0:3.1.0-3.el8_4.2 (rpm) before *
0:3.1.5-2.el8_6.1 (rpm) before *
0:3.1.5-2.el8_6.1 (rpm) before *
0:3.1.5-2.el8_6.1 (rpm) before *
0:3.1.7-1.el8_8.1 (rpm) before *
0:3.1.7-1.el8_8.1 (rpm) before *
0:3.1.9-2.el9_7.1 (rpm) before *
0:3.1.10-1.el9_8.1 (rpm) before *
0:3.1.5-3.el9_0.1 (rpm) before *
0:3.1.7-1.el9_2.1 (rpm) before *
0:3.1.8-1.el9_4.1 (rpm) before *
0:3.1.9-2.el9_6.1 (rpm) before *
Timeline
| 2026-04-01: | Reported to Red Hat. |
| 2026-04-01: | Made public. |
Credits
Red Hat would like to thank Sebastián Alba Vives for reporting this issue.
References
access.redhat.com/errata/RHSA-2026:13644 (RHSA-2026:13644)
access.redhat.com/errata/RHSA-2026:13657 (RHSA-2026:13657)
access.redhat.com/errata/RHSA-2026:13673 (RHSA-2026:13673)
access.redhat.com/errata/RHSA-2026:14205 (RHSA-2026:14205)
access.redhat.com/errata/RHSA-2026:14210 (RHSA-2026:14210)
access.redhat.com/errata/RHSA-2026:14211 (RHSA-2026:14211)
access.redhat.com/errata/RHSA-2026:14212 (RHSA-2026:14212)
access.redhat.com/errata/RHSA-2026:14213 (RHSA-2026:14213)
access.redhat.com/errata/RHSA-2026:14214 (RHSA-2026:14214)
access.redhat.com/errata/RHSA-2026:14215 (RHSA-2026:14215)
access.redhat.com/errata/RHSA-2026:14216 (RHSA-2026:14216)
access.redhat.com/errata/RHSA-2026:19043 (RHSA-2026:19043)
access.redhat.com/errata/RHSA-2026:19200 (RHSA-2026:19200)
access.redhat.com/errata/RHSA-2026:20916 (RHSA-2026:20916)
access.redhat.com/security/cve/CVE-2026-35092
bugzilla.redhat.com/show_bug.cgi?id=2453169
bugzilla.redhat.com/show_bug.cgi?id=2453814 (RHBZ#2453814)