Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-10649

Опубликовано: 16 июн. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pacemakerunfixedpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2026/06/16/6

  • https://github.com/clusterLabs/pacemaker/pull/4128

  • Fixed by: https://github.com/ClusterLabs/pacemaker/commit/8e667ef87ac4bc66ab8c64599334b521655925f7

  • Fixed by: https://github.com/ClusterLabs/pacemaker/commit/1e1825bf2c28a349c576521fbda4393455297987

  • Fixed by: https://github.com/ClusterLabs/pacemaker/commit/bb37829e00c782071906305d2cf50247179f0fd7

  • Fixed by: https://github.com/ClusterLabs/pacemaker/commit/6dd7ce8e656b6c629d3268038d6606041460fae7

  • Fixed by: https://github.com/ClusterLabs/pacemaker/commit/c49b26cb1e11bb160198a28ac5567b0154b49121

EPSS

Процентиль: 43%
0.00561
Низкий

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
redhat
около 2 месяцев назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

CVSS3: 8.6
nvd
около 1 месяца назад

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

suse-cvrf
около 1 месяца назад

Security update for pacemaker

suse-cvrf
28 дней назад

Security update for pacemaker

EPSS

Процентиль: 43%
0.00561
Низкий