Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Ubuntu 25.10 Corosync Faces Critical DoS Vulnerability 2026-35091

Ubuntu Large Esm H500
Several security issues were fixed in Corosync.
==========================================================================
Ubuntu Security Notice USN-8170-1
April 13, 2026

corosync vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in Corosync.

Software Description:
- corosync: cluster engine daemon and utilities

Details:

It was discovered that Corosync incorrectly handled the membership commit
token validity check. A remote attacker could use this issue to cause
Corosync to crash, resulting in a denial of service, or to possibly obtain
a small quantity of sensitive information. (CVE-2026-35091)

It was discovered that Corosync incorrectly handled join message
validation. A remote attacker could possibly use this issue to cause
Corosync to crash, resulting in a denial of service. (CVE-2026-35092)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  corosync                        3.1.9-2ubuntu1.1

Ubuntu 24.04 LTS
  corosync                        3.1.7-1ubuntu3.2

Ubuntu 22.04 LTS
  corosync                        3.1.6-1ubuntu1.2

After a standard system update you need to restart Corosync to make all the
necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8170-1
  CVE-2026-35091, CVE-2026-35092

Package Information:
  https://launchpad.net/ubuntu/+source/corosync/3.1.9-2ubuntu1.1
  https://launchpad.net/ubuntu/+source/corosync/3.1.7-1ubuntu3.2
  https://launchpad.net/ubuntu/+source/corosync/3.1.6-1ubuntu1.2

Ubuntu 25.10 Corosync Faces Critical DoS Vulnerability 2026-35091

ubuntu
Calendar Grey April 13, 2026
Dist Ubuntu Esm H88
Critical security flaws in Corosync for Ubuntu can lead to service disruptions and exposure of sensitive data.
Several security issues were fixed in Corosync.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Corosync. Software Description: - corosync: cluster engine daemon and utilities Details: It was discovered that Corosync incorrectly handled the membership commit token validity check. A remote attacker could use this issue to cause Corosync to crash, resulting in a denial of service, or to possibly obtain a small quantity of sensitive information. (CVE-2026-35091) It was discovered that Corosync incorrectly handled join message validation. A remote attacker could possibly use this issue to cause Corosync to crash, resulting in a denial of service. (CVE-2026-35092)

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 corosync 3.1.9-2ubuntu1.1 Ubuntu 24.04 LTS corosync 3.1.7-1ubuntu3.2 Ubuntu 22.04 LTS corosync 3.1.6-1ubuntu1.2 After a standard system update you need to restart Corosync to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8170-1

CVE-2026-35091, CVE-2026-35092

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8170-1

Package Information

https://launchpad.net/ubuntu/+source/corosync/3.1.9-2ubuntu1.1 https://launchpad.net/ubuntu/+source/corosync/3.1.7-1ubuntu3.2 https://launchpad.net/ubuntu/+source/corosync/3.1.6-1ubuntu1.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here