CVE-2026-35091
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents. This vulnerability affects Corosync when running in totemudp/totemudpu mode, which is the default configuration.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
- EPSS probability
- 0.87%
- CWE
- CWE-253
- Published
- 2026-04-01
- Last modified
- 2026-08-21
Affected products
- Red Hat Red Hat Enterprise Linux 10
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
- Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Weakness type
Related vulnerabilities
- CVE-2026-15686 — Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability
- CVE-2026-59847 — Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification
- CVE-2026-5818 — MCU Firmware Update Authentication Bypass on Caliptra Core
- CVE-2026-46419 — Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a...
- CVE-2026-43863 — mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
- CVE-2026-35340 — uutils coreutils chown and chgrp False Success Exit Code in Recursive Mode
- CVE-2026-35339 — uutils coreutils chmod False Success Exit Code in Recursive Mode
- CVE-2026-0648 — The vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in...