A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
AIONLYREPORT package: pacemaker-3.0.1-5.el10 ------ Summary: Integer Overflow in Remote Message Decompression: crafted pre-auth compressed remote messages can wrap size calculations before allocation, leading to memory corruption and denial of service in the CIB remote listener. Requirements to exploit: Network reachability to a pacemaker-based CIB remote listener configured with remote-port or remote-tls-port, and the ability to send a crafted compressed remote message before authentication. The reproduction below demonstrates the fault on a 32-bit build with a memory sanitizer. Component affected: pacemaker-3.0.1-5.el10, lib/common/remote.c, pcmkremotemessagexml(), with the pre-auth call path through the CIB remote listener in daemons/based/basedremote.c Version affected: pacemaker-3.0.1-5.el10 when the CIB remote listener is enabled; the supplied reproduction demonstrates impact on a 32-bit build Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - 7.5 (HIGH) AV:N - The vulnerable parser is reachable over the network when the CIB remote listener is enabled. AC:L - The malformed header values and compressed payload are straightforward to construct. PR:N - The message is parsed before authentication. UI:N - No user interaction is required. S:U - The demonstrated impact is within the scope of the service handling the remote message. C:N - The available evidence does not establish unauthorized disclosure of data. I:N - The available evidence does not establish unauthorized modification of data. A:H - A crafted message can trigger memory corruption and crash the service during decompression. Impact: Important. Red Hat classifies flaws that allow remote users to cause a denial of service as Important. Here, an unauthenticated network client can reach the vulnerable parser before authentication and trigger a crash where the CIB remote listener is enabled. This is not Critical because the available evidence supports availability impact, not unauthenticated code execution or broader system compromise. Embargo: yes Reason: The issue is pre-auth and network-reachable when the listener is enabled, the malformed packet is straightforward to build, and no released fix is established yet. Acknowledgement: Aisle Research Vulnerability Details: In the remote message decompression path, attacker-controlled header values are used in size calculations before allocation: c if (header->payloadcompressed) { int rc = 0; unsigned int sizeu = 1 + header->payloaduncompressed; char uncompressed = pcmkassertalloc(1, header->payloadoffset + sizeu); ... rc = BZ2bzBuffToBuffDecompress(uncompressed + header->payloadoffset, &sizeu, remote->buffer + header->payloadoffset, header->payloadcompressed, 1, 0); payloadoffset, payloadcompressed, and payloaduncompressed are taken from the received remote message header, and there are no preceding bounds or consistency checks on these fields before sizeu and the allocation length are derived. A crafted message can therefore cause 1 + payloaduncompressed or payloadoffset + sizeu to wrap before allocation, leaving a small destination buffer while the decompressor is still asked to produce a much larger output region. This parsing occurs before client authentication on the CIB remote listener, so an unauthenticated client that can reach that listener can trigger the vulnerable path before cibremoteauth() completes. The available evidence supports a denial-of-service outcome through memory corruption and crash. It does not establish confidentiality, integrity, or code-execution impact, so those effects should be treated as unproven. Steps to reproduce: 1. Build and run a 32-bit pacemaker-based with ASan or another memory sanitizer, and enable remote-port or remote-tls-port. 2. Connect to the CIB remote listener and send one packet with payloadoffset = 0x00000028, payloaduncompressed = 0xFFFFFFC0, payloadcompressed = len(bz2payload) where bz2payload = bz2.compress(b"A"512 + b"\x00"), and sizetotal = payloadoffset + payloadcompressed. 3. Send the header and bz2payload as a single remote message. 4. Observe an out-of-bounds write or crash inside or immediately around BZ2bzBuffToBuffDecompress() from pcmkremotemessagexml() before authentication completes. Note: payloaduncompressed = UINT32MAX alone is not the best trigger. Values near UINT32MAX that make payloadoffset + (1 + payloaduncompressed) wrap are the more reliable case. Mitigation: Disable the CIB remote listener where it is not required. If it must remain enabled, restrict network access to trusted peers only. These steps reduce exposure but do not correct the underlying validation flaw. Proposed Fix: Validate header layout and sizes before decompression, and use overflow-safe arithmetic for the allocation size. diff diff --git a/lib/common/remote.c b/lib/common/remote.c @@ -300,10 +300,34 @@ pcmkremotemessagexml(pcmkremotet remote) / Support compression on the receiving end now, in case we ever want to add it later / if (header->payloadcompressed) { int rc = 0; unsigned int sizeu = 1 + header->payloaduncompressed;
char uncompressed =
pcmkassertalloc(1, header->payloadoffset + sizeu); + sizet allocsize = 0; + unsigned int sizeu = 0; + char uncompressed = NULL; + + if (header->payloadoffset < sizeof(struct remoteheaderv0)) { + crmerr("Invalid remote payload offset %u", header->payloadoffset); + return NULL; + } + if (((sizet) header->payloadoffset + (sizet) header->payloadcompressed) + != (sizet) header->sizetotal) { + crmerr("Invalid remote payload sizing"); + return NULL; + } + if ((sizet) header->sizetotal > remote->bufferoffset) { + crmerr("Incomplete remote message buffer"); + return NULL; + } + if (header->payloaduncompressed >= UINTMAX) { + crmerr("Invalid remote uncompressed size %u", header->payloaduncompressed); + return NULL; + } + + sizeu = header->payloaduncompressed + 1U; + if ((sizet) header->payloadoffset > (SIZEMAX - (sizet) sizeu)) { + crmerr("Remote payload size overflow"); + return NULL; + } + allocsize = (sizet) header->payloadoffset + (sizet) sizeu; + uncompressed = pcmkassertalloc(1, allocsize);
crmtrace("Decompressing message data %d bytes into %d bytes", header->payloadcompressed, sizeu); ------ This report was generated using AI technology. Always review AI-generated content prior to use
Hello,
on behalf of Red Hat Product Security I'm writing to disclose a new vulnerability on Pacemaker software that upstream is making public today.
You can find the full report at the end of this message.
The patches for this vulnerability can be found at: https://github.com/clusterLabs/pacemaker/pull/4128
The CVE ID should be published to CVE.ORG later today. Please let me know if you have any questions.
Thanks,
==== CVE Report ====
CVE-2026-10649 CVSSv3.1: 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Severity rating (https://access.redhat.com/security/updates/classification/): Important
Description:
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can cause the affected service to crash.
Acknowledgements: Found by AISLE in partnership with Red Hat
Notes: Although the original report mentions only the DoS as a consequence, it doesn't rule out further memory corruption or RCE (although unlikely). Because of this, we decided to adopt CI:L in CVSS as the attacker may be able to corrupt in-memory sensitive data or, in some cases, use this vulnerability to try to exfiltrate data, but the lack of total control over which data is corrupted seems very unlikely.
Original Report: Summary: Integer Overflow in Remote Message Decompression: crafted pre-auth compressed remote messages can wrap size calculations before allocation, leading to memory corruption and denial of service in the CIB remote listener. Requirements to exploit: Network reachability to a pacemaker-based CIB remote listener configured with remote-port or remote-tls-port, and the ability to send a crafted compressed remote message before authentication. The reproduction below demonstrates the fault on a 32-bit build with a memory sanitizer. Component affected: pacemaker-3.0.1-5.el10, lib/common/remote.c, pcmkremotemessagexml(), with the pre-auth call path through the CIB remote listener in daemons/based/basedremote.c
Vulnerability Details: In the remote message decompression path, attacker-controlled header values are used in size calculations before allocation: c if (header->payloadcompressed) { int rc = 0; unsigned int sizeu = 1 + header->payloaduncompressed; char uncompressed = pcmkassertalloc(1, header->payloadoffset + sizeu); ... rc = BZ2bzBuffToBuffDecompress(uncompressed + header->payloadoffset, &sizeu, remote->buffer + header->payloadoffset, header->payloadcompressed, 1, 0); payloadoffset, payloadcompressed, and payloaduncompressed are taken from the received remote message header, and there are no preceding bounds or consistency checks on these fields before sizeu and the allocation length are derived. A crafted message can therefore cause 1 + payloaduncompressed or payloadoffset + sizeu to wrap before allocation, leaving a small destination buffer while the decompressor is still asked to produce a much larger output region. This parsing occurs before client authentication on the CIB remote listener, so an unauthenticated client that can reach that listener can trigger the vulnerable path before cibremoteauth() completes. The available evidence supports a denial-of-service outcome through memory corruption and crash. It does not establish confidentiality, integrity, or code-execution impact, so those effects should be treated as unproven. Steps to reproduce: 1. Build and run a 32-bit pacemaker-based with ASan or another memory sanitizer, and enable remote-port or remote-tls-port. 2. Connect to the CIB remote listener and send one packet with payloadoffset = 0x00000028, payloaduncompressed = 0xFFFFFFC0, payloadcompressed = len(bz2payload) where bz2payload = bz2.compress(b"A"512 + b"\x00"), and sizetotal = payloadoffset + payloadcompressed. 3. Send the header and bz2payload as a single remote message. 4. Observe an out-of-bounds write or crash inside or immediately around BZ2bzBuffToBuffDecompress() from pcmkremotemessagexml() before authentication completes. Note: payloaduncompressed = UINT32MAX alone is not the best trigger. Values near UINT32MAX that make payloadoffset + (1 + payloaduncompressed) wrap are the more reliable case. Mitigation: Disable the CIB remote listener where it is not required. If it must remain enabled, restrict network access to trusted peers only. These steps reduce exposure but do not correct the underlying validation flaw.
Marco Benatto Red Hat Product Security secalert () redhat com for urgent response
Franck Grosjean of Red Hat reports:
Description of problem: acl definitions are not enforced and could be bypassed by a user without write access to the cib
Version-Release number of selected component (if applicable): RedHat Enterprise Linux 6.6 pcs --version = 0.9.123 pacemakerd --version = Pacemaker 1.1.11
How reproducible: a user with a read-only role can assign any other existing roles to himself and then gain any kind of access from any role (rw access to the cib if this kind of role exist).
Steps to Reproduce: 1. create a role read-only pcs acl role create read-only description="Read only access" read xpath /cib 2. create a role admin pcs acl role create admin description="Admin access" write xpath /cib 3. create an account (local + pcs) 4. open a session with this roaccount account 5. add admin role to your account pcs acl role assign admin to rocluster 6. check new acl pushed as a read-only user pcs acl User: rocluster Roles: read-only admin Role: read-only Description: Read only access Permission: read xpath /cib (read-only-read) Role: admin Description: Admin access Permission: write xpath /cib (admin-write) 7. add/delete/modify anything
Actual results: obtain rw access to the cib
Expected results: must not be possible with read-only access to the cib to assign a role
Additional info:
Introduced in: https://github.com/ClusterLabs/pacemaker/commit/f242c1ef Fixed in: https://github.com/ClusterLabs/pacemaker/commit/84ac07c