[CLSA-2026:1777742234] corosync: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-02 17:17:19 UTC
Description:
- CVE-2026-35091: fix incorrect return value in check_memb_commit_token_sanity allowing DoS via crafted memb_commit_token packet - CVE-2026-35092: fix integer overflow in check_memb_join_sanity allowing bypass of length validation via crafted memb_join packet
Updated packages:
  • corosync-3.1.9-2.el9_6.tuxcare.els1.x86_64.rpm
    sha:7acc61d3299f2a090d0e589f48b2daa9a7b6cc30f7d416bd12f92af2be2f9dfa
  • corosync-vqsim-3.1.9-2.el9_6.tuxcare.els1.x86_64.rpm
    sha:b79bfd48399a734ab7e3cfdb23123d00684013b52908280705acfbf75a3f3668
  • corosynclib-3.1.9-2.el9_6.tuxcare.els1.i686.rpm
    sha:1e470f4ee91df2fefd29198cefbc6d696bd840ca0030b351842d5b488c142610
  • corosynclib-3.1.9-2.el9_6.tuxcare.els1.x86_64.rpm
    sha:715ce335a55f09acc6d0a463e1a2e3f66c231814f1de93b8a5b79e7fee6e61fe
  • corosynclib-devel-3.1.9-2.el9_6.tuxcare.els1.i686.rpm
    sha:572d329ea9279c8fc75a4500257b5be4f50bdd1ed82ebb78931fdec622c94c21
  • corosynclib-devel-3.1.9-2.el9_6.tuxcare.els1.x86_64.rpm
    sha:7706b38827e340e8e2625c4be60e8c38ed0d48d49c8027700f5268d80559b89a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.