{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/corosync/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:corosync:corosync:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-81665"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Corosync"],"_cs_severities":["high"],"_cs_tags":["vulnerability","heap-overflow","dos"],"_cs_type":"advisory","_cs_vendors":["Corosync"],"content_html":"\u003cp\u003eCVE-2026-81665 describes a critical heap-based buffer overflow vulnerability in the Totem Process Group (totempg) message reassembly logic within the Corosync daemon. The flaw exists because the buffer allocated for reassembling fragmented multicast messages lacks sufficient runtime bounds checking in release builds. Corosync is a core cluster membership and messaging system commonly used in Linux high-availability environments. An attacker located on the local network segment, capable of injecting multicast traffic, can send malformed packets to the cluster. By triggering the buffer overflow, the attacker can cause a denial of service by crashing the Corosync daemon, which disrupts the cluster services. Given the nature of heap corruption, this vulnerability also presents a potential path for remote code execution if the attacker can exercise precise control over heap layout and state. This issue is particularly significant for environments that rely on cluster availability for mission-critical services.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes a presence on the local network segment (L2/L3 adjacency).\u003c/li\u003e\n\u003cli\u003eAttacker crafts malformed, fragmented multicast messages designed to exceed pre-allocated buffer sizes.\u003c/li\u003e\n\u003cli\u003eAttacker injects the crafted multicast packets onto the cluster's private interconnect network.\u003c/li\u003e\n\u003cli\u003eCorosync daemon receives and processes the malicious multicast fragment.\u003c/li\u003e\n\u003cli\u003eThe totempg component performs reassembly without enforcing runtime bounds checking.\u003c/li\u003e\n\u003cli\u003eThe heap buffer overflow occurs, overwriting adjacent memory structures with attacker-controlled data.\u003c/li\u003e\n\u003cli\u003eThe Corosync daemon crashes due to memory corruption, leading to service disruption or node fencing.\u003c/li\u003e\n\u003cli\u003eIf heap state is sufficiently controlled, the attacker gains the ability to overwrite function pointers or other control flow structures, enabling arbitrary code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe threat to cluster integrity and availability. Successful exploitation typically results in an immediate crash of the Corosync daemon, causing a denial of service (DoS) for all services managed by the cluster. In enterprise environments, this can lead to massive service outages, data inconsistency, and potential loss of data access. Depending on the environment, an attacker achieving code execution would gain the privileges of the user running the Corosync daemon, which is typically the root or a highly privileged service account.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the patching of all cluster nodes running the vulnerable Corosync daemon. Monitor cluster health for unexpected daemon restarts or nodes being fenced from the cluster, as these may indicate exploitation attempts. Utilize network segmentation to restrict access to the multicast traffic used by the cluster to only trusted infrastructure nodes.\u003c/p\u003e\n","date_modified":"2026-09-04T09:25:00Z","date_published":"2026-09-04T09:25:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-corosync-totempg-overflow/","summary":"A heap-based buffer overflow in the Corosync Totem Process Group component allows a network-adjacent attacker to crash the cluster or potentially execute arbitrary code via crafted multicast messages.","title":"Heap-Based Buffer Overflow in Corosync Totem Process Group","url":"https://feed.craftedsignal.io/briefs/2026-09-corosync-totempg-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Corosync","version":"https://jsonfeed.org/version/1.1"}