← Back

Corosync

corosync

Vendor: Corosync • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Corosync
Redhat
3Corosync
Enterprise LinuxOpenshift
Jun 17, 2026
Apr 1, 2026
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause...Show more
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.Show less
2Corosync
Redhat
3Corosync
Enterprise LinuxOpenshift
Jun 17, 2026
Apr 1, 2026
N/A· v4
8.2 HIGH· v3
N/A· v2
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (U...Show more
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contentsShow less
1Corosync
1Corosync
Jun 17, 2026
Mar 22, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.
4Canonical
CorosyncDebian+1 more
4Corosync
Debian LinuxEnterprise Linux Server+1 more
Nov 21, 2024
Apr 12, 2018
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.
1Corosync
1Corosync
May 6, 2026
Jun 6, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet.