Heap-Based Buffer Overflow in Corosync's Totem Process Group
CVE-2026-81665

7.5HIGH

What is CVE-2026-81665?

A heap-based buffer overflow has been identified in Corosync's Totem Process Group, affecting its ability to properly handle fragmented multicast messages. The vulnerability arises from the lack of a runtime bounds check in the buffer used during the reassembly of message fragments. A potential network adversary can exploit this by sending specially crafted multicast protocol messages to the Corosync cluster, leading to a heap buffer overflow that can crash the Corosync daemon. This incident not only disrupts service to the entire cluster but also opens the door for possible further exploitation through heap corruption.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Tristan Madani (Talence Security) for reporting this issue.
.