CVE-2026-35092 Details
Description
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use totemudp/totemudpu mode.
An integer overflow vulnerability has been identified in Corosync's join message validation, specifically in deployments using totemudp/totemudpu mode. This flaw allows remote, unauthenticated attackers to send crafted UDP packets that exploit the overflow, causing the service to crash and leading to a denial-of-service condition.
It is recommended to restrict network access to Corosync cluster communication ports. Configure firewall rules to limit incoming UDP traffic on the default port 5405 to only trusted hosts within the cluster. A service restart may be required for firewall changes to take effect.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| corosync corosync | All versions |
CPE
Remediation
| |
| redhat openshift | 4.0 |
CPE
Remediation
| |
| redhat enterprise linux | 7.0 8.0 9.0 10.0 |
CPE
Remediation
| |
Change History
14 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 21, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | CVE Modified | [email protected] |
| May 6, 2026 | CVE Modified | [email protected] |
| May 5, 2026 | CVE Modified | [email protected] |
| May 5, 2026 | CVE Modified | [email protected] |
| May 5, 2026 | CVE Modified | [email protected] |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |