RHSA-2026:14215: Moderate: corosync security update
Moderate: corosync security update
Other sources
The corosync packages provide the Corosync Cluster Engine and C APIs for Red Hat Enterprise Linux cluster software.Security Fix(es): corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet (CVE-2026-35091) corosync: Corosync: Denial of Service via integer overflow in join message validation (CVE-2026-35092) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:14215?
The severity of RHSA-2026:14215 is classified as moderate.
What is the main vulnerability addressed in RHSA-2026:14215?
RHSA-2026:14215 addresses a denial of service and information disclosure vulnerability via crafted UDP packets in Corosync.
How do I fix RHSA-2026:14215?
To fix RHSA-2026:14215, you should update the Corosync package to version 3.1.0-3.el8_4.2 or later.
Which systems are affected by RHSA-2026:14215?
RHSA-2026:14215 affects several versions of Red Hat Enterprise Linux, including those with High Availability and Extended Update Support.
Is there a known exploit for RHSA-2026:14215?
As of now, specific details about known exploits for RHSA-2026:14215 have not been publicly disclosed.