Executive brief
A vulnerability has been identified in Corosync, a core component used to manage high-availability clusters in Linux environments. An attacker can send specially crafted network packets to crash the service, causing a denial-of-service condition. This disruption can prevent servers in a cluster from communicating correctly, potentially leading to application downtime or service outages.
Technical details
An integer overflow vulnerability exists in Corosync's join message sanity validation logic. The flaw is triggered when the service processes crafted User Datagram Protocol (UDP) packets, specifically affecting deployments configured to use totemudp or totemudpu modes. A remote, unauthenticated attacker can exploit this by sending malicious packets to the cluster engine, leading to a service crash (Denial of Service). The vulnerability is rooted in CWE-190 (Integer Overflow or Wraparound). Patches have been released by Red Hat for various Enterprise Linux versions to address this issue.
Affected products
- Corosync Corosync 3.1.8, 3.1.9
- Red Hat Enterprise Linux 7.0, 8.0, 9.0, 10.0
- Red Hat OpenShift 4.0
Timeline
- 2026-04-01: disclosed: Initial disclosure of CVE-2026-35092
- 2026-04-01: advisory: NVD publication date
- 2026-05-05: patched: Red Hat released security updates (RHSA-2026:13644, RHSA-2026:13657)
References
- https://access.redhat.com/errata/RHSA-2026:13644
- https://access.redhat.com/errata/RHSA-2026:13657
- https://access.redhat.com/errata/RHSA-2026:13673
- https://access.redhat.com/errata/RHSA-2026:14205
- https://access.redhat.com/errata/RHSA-2026:14210
- https://access.redhat.com/errata/RHSA-2026:14211
- https://access.redhat.com/errata/RHSA-2026:14212