Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orftokenendian_convert in exec/totemsrp.c via a large UDP packet.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "corosync" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "corosync-dbgsym" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "corosync-doc" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "corosync-notifyd" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "corosync-notifyd-dbgsym" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "corosync-vqsim" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "corosync-vqsim-dbgsym" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcfg-dev" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcfg7" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcfg7-dbgsym" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcmap-dev" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcmap4" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcmap4-dbgsym" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcorosync-common-dev" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcorosync-common4" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcorosync-common4-dbgsym" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcpg-dev" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcpg4" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libcpg4-dbgsym" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libquorum-dev" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libquorum5" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libquorum5-dbgsym" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libsam-dev" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libsam4" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libsam4-dbgsym" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libvotequorum-dev" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libvotequorum8" }, { "binary_version": "3.0.3-2ubuntu2.2", "binary_name": "libvotequorum8-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "corosync" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "corosync-dbgsym" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "corosync-doc" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "corosync-notifyd" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "corosync-notifyd-dbgsym" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "corosync-vqsim" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "corosync-vqsim-dbgsym" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcfg-dev" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcfg7" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcfg7-dbgsym" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcmap-dev" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcmap4" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcmap4-dbgsym" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcorosync-common-dev" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcorosync-common4" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcorosync-common4-dbgsym" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcpg-dev" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcpg4" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libcpg4-dbgsym" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libquorum-dev" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libquorum5" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libquorum5-dbgsym" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libsam-dev" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libsam4" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libsam4-dbgsym" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libvotequorum-dev" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libvotequorum8" }, { "binary_version": "3.1.6-1ubuntu1.1", "binary_name": "libvotequorum8-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "corosync" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "corosync-dbgsym" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "corosync-doc" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "corosync-notifyd" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "corosync-notifyd-dbgsym" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "corosync-vqsim" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "corosync-vqsim-dbgsym" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcfg-dev" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcfg7" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcfg7-dbgsym" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcmap-dev" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcmap4" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcmap4-dbgsym" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcorosync-common-dev" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcorosync-common4" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcorosync-common4-dbgsym" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcpg-dev" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcpg4" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libcpg4-dbgsym" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libquorum-dev" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libquorum5" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libquorum5-dbgsym" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libsam-dev" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libsam4" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libsam4-dbgsym" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libvotequorum-dev" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libvotequorum8" }, { "binary_version": "3.1.8-2ubuntu1.1", "binary_name": "libvotequorum8-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "corosync" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "corosync-dbgsym" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "corosync-doc" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "corosync-notifyd" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "corosync-notifyd-dbgsym" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "corosync-vqsim" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "corosync-vqsim-dbgsym" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcfg-dev" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcfg7" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcfg7-dbgsym" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcmap-dev" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcmap4" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcmap4-dbgsym" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcorosync-common-dev" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcorosync-common4" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcorosync-common4-dbgsym" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcpg-dev" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcpg4" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libcpg4-dbgsym" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libquorum-dev" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libquorum5" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libquorum5-dbgsym" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libsam-dev" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libsam4" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libsam4-dbgsym" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libvotequorum-dev" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libvotequorum8" }, { "binary_version": "3.1.7-1ubuntu3.1", "binary_name": "libvotequorum8-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.1.8-3ubuntu2", "binary_name": "corosync" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "corosync-dbgsym" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "corosync-doc" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "corosync-notifyd" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "corosync-notifyd-dbgsym" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "corosync-vqsim" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "corosync-vqsim-dbgsym" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcfg-dev" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcfg7" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcfg7-dbgsym" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcmap-dev" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcmap4" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcmap4-dbgsym" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcorosync-common-dev" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcorosync-common4" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcorosync-common4-dbgsym" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcpg-dev" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcpg4" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libcpg4-dbgsym" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libquorum-dev" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libquorum5" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libquorum5-dbgsym" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libsam-dev" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libsam4" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libsam4-dbgsym" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libvotequorum-dev" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libvotequorum8" }, { "binary_version": "3.1.8-3ubuntu2", "binary_name": "libvotequorum8-dbgsym" } ] }