Source: corosync Version: 3.1.10-4 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for corosync. CVE-2026-81665[0]: | A heap-based buffer overflow was found in Corosync's Totem Process | Group (totempg) message reassembly. When processing fragmented | multicast messages, the buffer used to reassemble fragments lacks a | runtime bounds check in release builds. A network-adjacent attacker | able to send crafted multicast protocol messages to the cluster | could cause a heap buffer overflow with attacker-controlled data. | This can crash the Corosync daemon, causing a denial of service to | the entire cluster, and may potentially allow further exploitation | given sufficient heap-corruption control. CVE-2026-81666[1]: | An integer overflow was found in Corosync's handling of membership | commit token messages. The length-validation check for these | messages can be bypassed on 32-bit systems due to an integer | overflow in the calculation of the expected message length, allowing | a crafted network packet to trigger an out-of-bounds memory access | that crashes the Corosync daemon. This results in a denial of | service for the affected cluster node. The overflow does not occur | on 64-bit systems, where the length calculation is correctly | performed in 64-bit arithmetic. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-81665 https://www.cve.org/CVERecord?id=CVE-2026-81665 https://github.com/corosync/corosync/commit/5148bf07dffa61bcfa92ca2c058e7d0f0a981cf3 [1] https://security-tracker.debian.org/tracker/CVE-2026-81666 https://www.cve.org/CVERecord?id=CVE-2026-81666 https://github.com/corosync/corosync/commit/83920f2e36b5f1acd7dcf033c0820043cc29f82a Please adjust the affected versions in the BTS as needed. Regards, Salvatore

