Executive brief
A vulnerability has been identified in Corosync, a core component used to manage high-availability clusters in Linux environments. An unauthenticated attacker can send a specially crafted network packet to crash the service or potentially view small amounts of sensitive system memory. This could lead to a total loss of availability for the cluster and its hosted applications, as well as a limited risk of data exposure.
Technical details
A flaw exists in the Corosync membership commit token sanity check due to an incorrect check of a function return value (CWE-253). By sending a specially crafted UDP packet, a remote unauthenticated attacker can trigger an out-of-bounds read. This vulnerability specifically affects Corosync when running in totemudp or totemudpu modes, which are the default configurations. Successful exploitation can result in a denial of service (DoS) by crashing the cluster engine or the disclosure of limited memory contents. Patches have been released by Red Hat for Enterprise Linux versions 8, 9, and 10.
Affected products
- Corosync Corosync Cluster Engine 3.1.8, 3.1.9
- Red Hat Enterprise Linux 8, 9, 10
- Red Hat OpenShift 4.0
Timeline
- 2026-04-01: disclosed: Initial disclosure date
- 2026-05-05: patched: Red Hat released security updates (RHSA-2026:13644, RHSA-2026:13657)
References
- https://access.redhat.com/errata/RHSA-2026:13644
- https://access.redhat.com/errata/RHSA-2026:13657
- https://access.redhat.com/errata/RHSA-2026:13673
- https://access.redhat.com/errata/RHSA-2026:14205
- https://access.redhat.com/errata/RHSA-2026:14210
- https://access.redhat.com/errata/RHSA-2026:14211
- https://access.redhat.com/errata/RHSA-2026:14212