RHSA-2026:14216: Moderate: corosync security update
Moderate: corosync security update
Other sources
The corosync packages provide the Corosync Cluster Engine and C APIs for Red Hat Enterprise Linux cluster software.Security Fix(es): corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet (CVE-2026-35091) corosync: Corosync: Denial of Service via integer overflow in join message validation (CVE-2026-35092) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:14216?
The severity of RHSA-2026:14216 is classified as moderate.
How do I fix RHSA-2026:14216?
To fix RHSA-2026:14216, update the corosync package to version 3.1.7-1.el8_8.1 or later.
What security issues are addressed in RHSA-2026:14216?
RHSA-2026:14216 addresses a denial of service and information disclosure vulnerability via crafted UDP packets in corosync.
Which systems are affected by RHSA-2026:14216?
Red Hat Enterprise Linux and Red Hat High Availability systems are affected by RHSA-2026:14216.
When was RHSA-2026:14216 released?
RHSA-2026:14216 was released on August 10, 2026.