Remote Vulnerability in Corosync Affects Membership Commit Token
CVE-2026-35091
Key Information:
What is CVE-2026-35091?
A vulnerability exists in Corosync, specifically related to the membership commit token's sanity check. An unauthenticated attacker can exploit this flaw by sending a specially crafted User Datagram Protocol (UDP) packet, leading to an out-of-bounds read situation. This exploitation can cause a denial of service (DoS) by disrupting the normal operation of Corosync and may unintentionally reveal sensitive memory contents. This issue is particularly relevant when Corosync operates in its default configuration using totemudp/totemudpu mode.
Affected Version(s)
Red Hat Enterprise Linux 10 0:3.1.9-2.el10_1.1
Red Hat Enterprise Linux 10 0:3.1.10-1.el10_2.1
Red Hat Enterprise Linux 10.0 Extended Update Support 0:3.1.9-1.el10_0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved