CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Corosync Redhat3Corosync Enterprise LinuxOpenshiftJun 17, 2026 Apr 1, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause...Show more |
2Corosync Redhat3Corosync Enterprise LinuxOpenshiftJun 17, 2026 Apr 1, 2026 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (U...Show more |
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet. |
4Canonical CorosyncDebian+1 more4Corosync Debian LinuxEnterprise Linux Server+1 moreNov 21, 2024 Apr 12, 2018 N/A· v4 7.5 HIGH· v3 7.5 HIGH· v2 corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c. |
The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet. |