Corosync TotemPG Heap Overflow (CVE-2026-81665)
CVE-2026-81665 Published on September 4, 2026
Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
Vulnerability Analysis
Timeline
Reported to Red Hat.
Made public. 12 days later.
Weakness Type
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Products Associated with CVE-2026-81665
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
Red Hat Enterprise Linux 10:- Version 0:3.1.10-1.el10_2.2 and below * is unaffected.
- Version 0:3.1.9-1.el10_0.3 and below * is unaffected.
- Version 0:2.4.5-7.el7_9.4 and below * is unaffected.
- Version 0:3.1.10-1.el9_8.2 and below * is unaffected.
- Version 0:3.1.7-1.el9_2.2 and below * is unaffected.
- Version 0:3.1.8-1.el9_4.2 and below * is unaffected.
- Version 0:3.1.9-2.el9_6.2 and below * is unaffected.