RHSA-2026:14205: Moderate: corosync security update
Moderate: corosync security update
Other sources
The corosync packages provide the Corosync Cluster Engine and C APIs for Red Hat Enterprise Linux cluster software.Security Fix(es): corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet (CVE-2026-35091) corosync: Corosync: Denial of Service via integer overflow in join message validation (CVE-2026-35092) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:14205?
The severity of RHSA-2026:14205 is classified as Moderate.
What type of vulnerabilities are addressed in RHSA-2026:14205?
RHSA-2026:14205 addresses vulnerabilities related to Denial of Service and information disclosure via crafted UDP packets.
How do I fix RHSA-2026:14205?
To fix RHSA-2026:14205, you should update corosync to version 3.1.9-1.el10_0.2.
Which products are affected by RHSA-2026:14205?
RHSA-2026:14205 affects various Red Hat Enterprise Linux products including those for x86_64, Power, ARM 64, and IBM z Systems.
What is the main purpose of the corosync package in relation to RHSA-2026:14205?
The corosync package provides the Corosync Cluster Engine and C APIs for Red Hat Enterprise Linux cluster software.