DEBIAN-CVE-2026-81666

    Dashboard / Vulnerabilities / DEBIAN-CVE-2026-81666

    DEBIAN-CVE-2026-81666

    Published: 4 Sept 2026Last Modified: 9 Sept 2026
    Upstream:

    Summary:

    Details: An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic.

    Affected packages

    Package

    Name: corosync

    Purl: pkg:deb/debian/corosync?arch=source&distro=bookworm

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    3.1.10-1
    3.1.10-2
    3.1.10-3
    3.1.10-4
    3.1.7-1
    3.1.7-1+deb12u1
    3.1.7-1+deb12u2
    3.1.8-1
    3.1.8-2
    3.1.8-3
    3.1.9-1
    3.1.9-2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DEBIAN-CVE-2026-81666 | CVE-DB