Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
There is no complete mitigation for this vulnerability short of a fix, but the following steps significantly reduce risk: 1. Ensure cluster message authentication is enabled in corosync.conf: set crypto_cipher to aes256 and crypto_hash to sha256 (or stronger) in the totem {} block, with a shared key generated by corosync-keygen. This is the default when clusters are configured via 'pcs cluster setup', and disabling it (cipher=none/hash=none) is an explicitly unsupported configuration per upstream maintainer guidance. 2. Restrict network access to the cluster communication ports (default 5405-5412/UDP) to trusted cluster node addresses only, using firewalld or other firewall rules. 3. Ensure SELinux is running in enforcing mode on cluster nodes to limit the impact of any successful exploitation.
Fri, 04 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Corosync
Corosync corosync Redhat openshift Container Platform |
|
| Vendors & Products |
Corosync
Corosync corosync Redhat openshift Container Platform |
Fri, 04 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 04 Sep 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control. | |
| Title | Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-04T18:25:16.035Z
Reserved: 2026-08-27T10:38:28.793Z
Link: CVE-2026-81665
Updated: 2026-09-04T17:09:14.391Z
Status : Received
Published: 2026-09-04T09:17:11.357
Modified: 2026-09-04T19:17:28.993
Link: CVE-2026-81665
OpenCVE Enrichment
Updated: 2026-09-04T15:20:12Z