CVE-2026-35091 Details
Description
A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory contents
A vulnerability exists in Corosync's membership commit token sanity check, specifically in the default totemudp/totemudpu mode. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted UDP packet, causing an out-of-bounds read. This exploitation leads to a denial-of-service condition and may disclose limited memory contents. The issue arises because the check_memb_commit_token_sanity function incorrectly validates message lengths, allowing truncated messages to be processed and causing a heap-buffer-overflow read, as confirmed by AddressSanitizer.
To mitigate this vulnerability, restrict network access to the Corosync service on UDP port 5405 to trusted hosts or networks. If Corosync is not needed, consider disabling the service. After making these changes, a restart of the Corosync service or a system reboot may be required for the changes to take effect.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-253 | Incorrect Check of Function Return Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| corosync corosync | All versions |
CPE
Remediation
| |
| redhat openshift | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 13, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | CVE Modified | [email protected] |
| May 5, 2026 | CVE Modified | [email protected] |
| May 5, 2026 | CVE Modified | [email protected] |
| May 5, 2026 | CVE Modified | [email protected] |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |