Описание
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.
Отчет
This is an Important denial of service vulnerability in Corosync, affecting deployments configured to use totemudp/totemudpu mode. A remote, unauthenticated attacker can send specially crafted UDP packets to trigger an integer overflow, causing the Corosync service to crash.This issue affects Corosync only when using the legacy totemudp or totemudpu transports with unencrypted communication. These are not the default.The default transport is knet, which supports encryption and is the standard configuration in RHEL. The totemudp and totemudpu transports are unsupported in RHEL and require explicit manual configuration.
Меры по смягчению последствий
Systems using totemudp or totemudpu should migrate to the supported knet transport and enable encryption.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected | ||
| Red Hat Enterprise Linux 10 | corosync | Fixed | RHSA-2026:13644 | 05.05.2026 |
| Red Hat Enterprise Linux 10 | corosync | Fixed | RHSA-2026:19043 | 19.05.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | corosync | Fixed | RHSA-2026:14205 | 06.05.2026 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | corosync | Fixed | RHSA-2026:20916 | 26.05.2026 |
| Red Hat Enterprise Linux 8 | corosync | Fixed | RHSA-2026:13657 | 05.05.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | corosync | Fixed | RHSA-2026:14215 | 06.05.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | corosync | Fixed | RHSA-2026:14215 | 06.05.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | corosync | Fixed | RHSA-2026:14214 | 06.05.2026 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | corosync | Fixed | RHSA-2026:14214 | 06.05.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.
A flaw was found in Corosync. An integer overflow vulnerability in Cor ...
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.
EPSS
7.5 High
CVSS3