CVE-2026-35092 identifies a high-severity integer overflow vulnerability within Corosync's join message sanity validation, specifically affecting deployments configured with totemudp/totemudpu mode. A remote, unauthenticated attacker can exploit this flaw by sending crafted User Datagram Protocol (UDP) packets. This action can cause the Corosync service to crash, leading to a denial of service. With a CVSS score of 7.5, the attack complexity is low, requiring no user interaction or privileges. Currently, there is no evidence of active exploitation, public exploit code, or inclusion on CISA's Known Exploited Vulnerabilities catalog, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:corosync:corosync:-:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift:4.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.