https://seclists.org/oss-sec/2026/q2/944: Pacemaker: Denial of Service via integer overflow in mote message decompssion (CVE-2026-10649)
Published Jun 16, 2026
·Updated
Affected Software
2 affected components
ClusterLabs Pacemaker=3.0.1
redhat/pacemaker=3.0.1-5.el10
Frequently Asked Questions
1
What is the severity of CVE-2026-10649?
CVE-2026-10649 is classified as a denial of service vulnerability due to an integer overflow in the Pacemaker software.
2
How do I fix CVE-2026-10649?
To fix CVE-2026-10649, apply the patches provided by the ClusterLabs Pacemaker team.
3
What versions of Pacemaker are affected by CVE-2026-10649?
CVE-2026-10649 affects specific versions of the ClusterLabs Pacemaker software, so it is recommended to check with the latest advisory for detailed version information.
4
Is there a workaround for CVE-2026-10649 if I cannot apply the patch immediately?
Currently, there are no known workarounds for CVE-2026-10649, so patching is the recommended action.
5
What are the potential impacts of exploiting CVE-2026-10649?
Exploiting CVE-2026-10649 could lead to a denial of service, making the Pacemaker service unavailable.