CVE-2026-81665

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
Configurations

No configuration.

History

16 Sep 2026, 14:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:67879 -

16 Sep 2026, 13:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:67873 -

16 Sep 2026, 12:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:67872 -
  • () https://access.redhat.com/errata/RHSA-2026:67878 -
  • () https://access.redhat.com/errata/RHSA-2026:67881 -

Information

Published : 2026-09-04 09:17

Updated : 2026-09-16 14:17


NVD link : CVE-2026-81665

Mitre link : CVE-2026-81665

CVE.ORG link : CVE-2026-81665


JSON object : View

Products Affected

No product.

CWE
CWE-122

Heap-based Buffer Overflow