A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
References
Configurations
No configuration.
History
16 Sep 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Sep 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Sep 2026, 12:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Information
Published : 2026-09-04 09:17
Updated : 2026-09-16 14:17
NVD link : CVE-2026-81665
Mitre link : CVE-2026-81665
CVE.ORG link : CVE-2026-81665
JSON object : View
Products Affected
No product.
CWE
CWE-122
Heap-based Buffer Overflow
