DEBIAN-CVE-2026-81666
Dashboard / Vulnerabilities / DEBIAN-CVE-2026-81666
Summary:
Details: An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic.
Affected packages
Package
Name: corosync
Purl: pkg:deb/debian/corosync?arch=source&distro=bookworm
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -None
Affected versions
3.1.10-1
3.1.10-2
3.1.10-3
3.1.10-4
3.1.7-1
3.1.7-1+deb12u1
3.1.7-1+deb12u2
3.1.8-1
3.1.8-2
3.1.8-3
3.1.9-1
3.1.9-2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
