REDHAT-BUG-2453813: Medium severity corosync corosync vulnerability

Published Apr 1, 2026
·
Updated

Wrong return value vulnerability in the Corosync membership commit token sanity check in exec/totemsrp.c. The flaw occurs in checkmembcommittokensanity() where truncated messages (msglen < sizeof(struct membcommittoken)) incorrectly return 0 (success) instead of -1 (failure). As a result, messagehandlermembcommittoken() continues processing attacker-controlled, undersized input, performs an allocation based on the short length, and then accesses struct membcommittoken fields beyond the allocated region, triggering an out-of-bounds read (ASAN-confirmed). This can be exploited remotely without authentication in totemudp/totemudpu mode by sending a single crafted UDP packet to the Corosync port (default 5405), causing a denial of service and potentially leaking limited memory contents.

Affected Software

1 affected component
corosync corosync

Event History

Apr 1, 2026
Data Sourced
via Red Hat·11:31 AM
DescriptionSeverityAffected Software
Dec 7, 58232
Event
via Red Hat·12:57 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2453813?

The severity of REDHAT-BUG-2453813 has not been explicitly rated, but it involves a wrong return value that could potentially lead to security issues.

2

How do I fix REDHAT-BUG-2453813?

To fix REDHAT-BUG-2453813, you should apply the latest patches or updates provided by Corosync for the affected versions.

3

What could happen if REDHAT-BUG-2453813 is exploited?

If REDHAT-BUG-2453813 is exploited, it may allow truncated messages to be incorrectly processed, potentially impacting the stability of the Corosync service.

4

What versions of Corosync are affected by REDHAT-BUG-2453813?

All versions of Corosync that include the vulnerable code in exec/totemsrp.c are affected by REDHAT-BUG-2453813.

5

Is there a workaround for REDHAT-BUG-2453813 if I cannot apply a patch immediately?

Currently, there are no documented workarounds for REDHAT-BUG-2453813, so applying a patch is the recommended action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203