Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35092

Опубликовано: 01 апр. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.

Отчет

This is an Important denial of service vulnerability in Corosync, affecting deployments configured to use totemudp/totemudpu mode. A remote, unauthenticated attacker can send specially crafted UDP packets to trigger an integer overflow, causing the Corosync service to crash.This issue affects Corosync only when using the legacy totemudp or totemudpu transports with unencrypted communication. These are not the default.The default transport is knet, which supports encryption and is the standard configuration in RHEL. The totemudp and totemudpu transports are unsupported in RHEL and require explicit manual configuration.

Меры по смягчению последствий

Systems using totemudp or totemudpu should migrate to the supported knet transport and enable encryption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Enterprise Linux 10corosyncFixedRHSA-2026:1364405.05.2026
Red Hat Enterprise Linux 10corosyncFixedRHSA-2026:1904319.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportcorosyncFixedRHSA-2026:1420506.05.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportcorosyncFixedRHSA-2026:2091626.05.2026
Red Hat Enterprise Linux 8corosyncFixedRHSA-2026:1365705.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportcorosyncFixedRHSA-2026:1421506.05.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OncorosyncFixedRHSA-2026:1421506.05.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportcorosyncFixedRHSA-2026:1421406.05.2026
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicecorosyncFixedRHSA-2026:1421406.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2453814corosync: Corosync: Denial of Service via integer overflow in join message validation

EPSS

Процентиль: 59%
0.00994
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.

CVSS3: 7.5
nvd
4 месяца назад

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.

CVSS3: 7.5
debian
4 месяца назад

A flaw was found in Corosync. An integer overflow vulnerability in Cor ...

CVSS3: 7.5
github
4 месяца назад

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.

suse-cvrf
4 месяца назад

Security update for corosync

EPSS

Процентиль: 59%
0.00994
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-35092