CVE-2026-35091 details a high-severity vulnerability in Corosync, specifically affecting its default totemudp/totemudpu operating mode. A remote, unauthenticated attacker can exploit a flaw in the membership commit token sanity check by sending a specially crafted UDP packet. This low-complexity attack can lead to an out-of-bounds read, resulting in a denial of service and potential disclosure of limited memory contents. Rated with a CVSS score of 8.2 HIGH, the vulnerability poses a significant risk. Currently, there is no evidence of active exploitation, nor is public exploit code available, though it has generated some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:corosync:corosync:-:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift:4.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.