Corosync
Corosync: vulnerabilidades y CVE
Corosync tiene 7 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-81666 | Media (6.5) | 0.19% | — | 4 sept 2026 | An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of… |
| CVE-2026-81665 | Alta (7.5) | 0.35% | — | 4 sept 2026 | A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check… |
| CVE-2026-35092 | Alta (7.5) | 1.3% | — | 1 abr 2026 | A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause… |
| CVE-2026-35091 | Alta (8.2) | 1.1% | — | 1 abr 2026 | A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol… |
| CVE-2025-30472 | Crítica (9.8) | 0.46% | — | 22 mar 2025 | Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet. |
| CVE-2018-1084 | Alta (7.5) | 3.1% | — | 12 abr 2018 | corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c. |
| CVE-2013-0250 | Media (5) | 3.1% | — | 6 jun 2014 | The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.