Integer Overflow Vulnerability in Corosync Affects Cluster Node Stability
CVE-2026-81666
6.5MEDIUM
What is CVE-2026-81666?
An integer overflow vulnerability exists in Corosync's processing of membership commit token messages. On 32-bit systems, the length-validation mechanism can be circumvented due to incorrect calculations of expected message lengths, enabling crafted network packets to trigger out-of-bounds memory access. This leads to crashes of the Corosync daemon, effectively causing denial of service for the impacted cluster node. It is important to note that this vulnerability does not affect 64-bit systems where calculations are handled correctly.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Tristan Madani (Talence Security) for reporting this issue.