Junglewise Threat Intelligence

CVE-2026-81665: Corosync heap-based buffer overflow in Totem message reassembly

CVE-2026-81665 · Severity: high · CVSS 7.5 · Published 2026-09-04

Technologies: Corosync. Vendors: Corosync.

Executive brief

Corosync is cluster management software that enables multiple servers to communicate and coordinate as a unified system. A heap buffer overflow vulnerability in its message reassembly logic allows an attacker on the same network segment to send specially crafted cluster messages that can crash the Corosync daemon, disrupting cluster operations and potentially compromising the entire cluster infrastructure.

Technical details

A heap-based buffer overflow exists in Corosync's Totem Process Group (totempg) message reassembly component. When processing fragmented multicast messages, the reassembly buffer lacks proper runtime bounds checking in release builds, allowing an attacker with network adjacency to send crafted multicast protocol messages that overflow the buffer with attacker-controlled data. This can cause the Corosync daemon to crash (denial of service), and with sufficient control over heap corruption, may enable further arbitrary code execution. A patch is available via Red Hat security update RHSA-2026:67872.

Affected products

  • Corosync Corosync <UNKNOWN

Timeline

  • 2026-09-04: disclosed
  • 2026-09-16: advisory: Red Hat RHSA-2026:67872 issued

References

Related threats