Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-7201

Опубликовано: 16 мая 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-7201: corosync security update (MODERATE)

[3.1.9-2]

  • Resolves: RHEL-84616

  • totemsrp: Check size of orf_token msg (fixes CVE-2025-30472)

[3.1.9-1]

  • Resolves: RHEL-65699

  • New upstream release (RHEL-65699)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

corosync-vqsim

3.1.9-2.el9_6

corosynclib

3.1.9-2.el9_6

Oracle Linux x86_64

corosynclib

3.1.9-2.el9_6

corosync-vqsim

3.1.9-2.el9_6

Связанные CVE

Связанные уязвимости

CVSS3: 9
ubuntu
5 месяцев назад

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.

CVSS3: 6.6
redhat
5 месяцев назад

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.

CVSS3: 9
nvd
5 месяцев назад

Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.

CVSS3: 9
debian
5 месяцев назад

Corosync through 3.1.9, if encryption is disabled or the attacker know ...

suse-cvrf
4 месяца назад

Security update for corosync