Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20505-1

Опубликовано: 10 апр. 2026
Источник: suse-cvrf

Описание

Security update for corosync

This update for corosync fixes the following issues:

  • CVE-2026-35091: Denial of Service and information disclosure via crafted UDP packet (bsc#1261299).
  • CVE-2026-35092: Denial of Service via integer overflow in join message validation (bsc#1261300).

Список пакетов

openSUSE Leap 16.0
corosync-3.1.9-160000.3.1
corosync-devel-3.1.9-160000.3.1
corosync-libs-3.1.9-160000.3.1

Описание

A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents. This vulnerability affects Corosync when running in totemudp/totemudpu mode, which is the default configuration.


Затронутые продукты
openSUSE Leap 16.0:corosync-3.1.9-160000.3.1
openSUSE Leap 16.0:corosync-devel-3.1.9-160000.3.1
openSUSE Leap 16.0:corosync-libs-3.1.9-160000.3.1

Ссылки

Описание

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.


Затронутые продукты
openSUSE Leap 16.0:corosync-3.1.9-160000.3.1
openSUSE Leap 16.0:corosync-devel-3.1.9-160000.3.1
openSUSE Leap 16.0:corosync-libs-3.1.9-160000.3.1

Ссылки