VDB

CVE-2026-81665

CVE-2026-81665 PUBLISHED CVSS 7.5 HIGH

Reported by redhat · Published September 4, 2026

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 100:3.1.10-1.el10_2.2
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:3.1.9-1.el10_0.3
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:2.4.5-7.el7_9.4
Red HatRed Hat Enterprise Linux 90:3.1.10-1.el9_8.2
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:3.1.7-1.el9_2.2
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:3.1.8-1.el9_4.2
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:3.1.9-2.el9_6.2
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support0:3.1.9-1.el10_0.3, 0:3.1.9-1.el10_0.3, 0:3.1.9-1.el10_0.3
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Enterprise Linux 9.2 Update Services for SAP Solutions0:3.1.7-1.el9_2.2
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions0:3.1.8-1.el9_4.2, 0:3.1.8-1.el9_4.2, 0:3.1.8-1.el9_4.2
Red HatRed Hat Enterprise Linux 100:3.1.10-1.el10_2.2, 0:3.1.10-1.el10_2.2, 0:3.1.10-1.el10_2.2
Red HatRed Hat Enterprise Linux 7 Extended Lifecycle Support0:2.4.5-7.el7_9.4, 0:2.4.5-7.el7_9.4
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support0:3.1.9-2.el9_6.2, 0:3.1.9-2.el9_6.2, 0:3.1.9-2.el9_6.2

…and 1 more

Timeline

  • Sep 4, 2026 EPSS Score
  • Sep 4, 2026 CVE Published
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 Distribution Patch
  • Sep 16, 2026 Security Advisory
  • Sep 16, 2026 Distribution Patch
  • Sep 16, 2026 Security Advisory
  • Sep 16, 2026 Distribution Patch
  • Sep 16, 2026 Security Advisory
  • Sep 17, 2026 EPSS Score
  • Sep 17, 2026 Distribution Patch
  • Sep 17, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›