CVE-2025-30472: Buffer Overflow
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orftokenendianconvert in exec/totemsrp.c via a large UDP packet.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30472?
CVE-2025-30472 is rated as a critical severity vulnerability due to its potential to cause stack-based buffer overflow.
How do I fix CVE-2025-30472?
To fix CVE-2025-30472, update Corosync to version 3.2.0 or later where the vulnerability is patched.
What causes the CVE-2025-30472 vulnerability?
CVE-2025-30472 is caused by a stack-based buffer overflow in the orf_token_endian_convert function when handling overly large UDP packets.
Who is affected by CVE-2025-30472?
CVE-2025-30472 affects all Corosync versions up to and including 3.1.9 when encryption is disabled or if the encryption key is known to an attacker.
What can an attacker do using CVE-2025-30472?
An attacker exploiting CVE-2025-30472 can execute arbitrary code, potentially leading to a denial of service or unauthorized access.