Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99888.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99888
Upstream
  • CVE-2026-81665
Published
2026-09-04T09:17:11Z
Modified
2026-09-12T05:28:09Z
Summary
CVE-2026-81665 affecting package corosync 3.0.4-4
Details

A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.

References

Affected packages

Azure Linux:3 / corosync

Package

Name
corosync
Purl
pkg:rpm/azure-linux/corosync

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.0.4-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99888.json"