RHSA-2026:14214: Moderate: corosync security update
Moderate: corosync security update
Other sources
The corosync packages provide the Corosync Cluster Engine and C APIs for Red Hat Enterprise Linux cluster software.Security Fix(es): corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet (CVE-2026-35091) corosync: Corosync: Denial of Service via integer overflow in join message validation (CVE-2026-35092) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/corosyncto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1 - Upgrade
Upgrade
redhat/corosync-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1 - Upgrade
Upgrade
redhat/corosync-debugsourceto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1 - Upgrade
Upgrade
redhat/corosync-vqsim-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1 - Upgrade
Upgrade
redhat/corosynclibto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1 - Upgrade
Upgrade
redhat/corosynclib-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1 - Upgrade
Upgrade
redhat/spausedd-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1 - Upgrade
Upgrade
redhat/corosynclib-develto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1 - Upgrade
Upgrade
redhat/spauseddto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1 - Upgrade
Upgrade
redhat/corosync-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1.aa - Upgrade
Upgrade
redhat/corosync-debugsourceto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1.aa - Upgrade
Upgrade
redhat/corosync-vqsim-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1.aa - Upgrade
Upgrade
redhat/corosynclibto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1.aa - Upgrade
Upgrade
redhat/corosynclib-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1.aa - Upgrade
Upgrade
redhat/spausedd-debuginfoto a version that resolves this vulnerability.Fixed in 3.1.5-2.el8_6.1.aa - Upgrade
Upgrade
corosyncto a version that resolves this vulnerability.Patch CVE-2026-35092 - Upgrade
Upgrade
corosyncto a version that resolves this vulnerability.Patch CVE-2026-35091
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:14214?
The severity of RHSA-2026:14214 is classified as moderate.
What vulnerabilities are addressed in RHSA-2026:14214?
RHSA-2026:14214 addresses a denial of service and information disclosure vulnerability via crafted UDP packets.
How do I fix RHSA-2026:14214?
To fix RHSA-2026:14214, update the corosync packages to version 3.1.5-2.el8_6.1 or later.
Which Red Hat products are affected by RHSA-2026:14214?
RHSA-2026:14214 affects various versions of Red Hat Enterprise Linux, particularly those with corosync installed.
Is there a workaround for RHSA-2026:14214?
There is no official workaround for RHSA-2026:14214; applying the security update is recommended.