Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Two vulnerabilities have been found in corosync, a cluster engine daemon and utilities, that allow a remote, unauthenticated attacker to cause a denial of service. CVE-2026-35091 A remote unauthenticated attacker can exploit a wrong return value. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4608-1
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-13657 http://linux.oracle.com/errata/ELSA-2026-13657.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: corosync-vqsim-3.1.8-1.el8_10.1.x86_64.rpm corosynclib-3.1.8-1.el8_10.1.i686.rpm corosynclib-3.1.8-1.el8_10.1.x86_64.rpm aarch64: corosync-vqsim-3.1.8-1.el8_10.1.aarch64.rpm corosynclib-3.1.8-1.el8_10.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/corosync-3.1.8-1.el8_10.1.src.rpm Related CVEs: CVE-2026-35091 CVE-2026-35092 Description of changes: [3.1.8-1.1] - Resolves: RHEL-163805 - Resolves: RHEL-163826 - totemsrp: Return error if sanity check fails (fixes CVE-2026-35091) - totemsrp: Fix integer overflow in memb_join_sanity (fixes CVE-2026-35092) _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-13644 http://linux.oracle.com/errata/ELSA-2026-13644.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: corosync-vqsim-3.1.9-2.el10_1.1.x86_64.rpm corosynclib-3.1.9-2.el10_1.1.x86_64.rpm aarch64: corosync-vqsim-3.1.9-2.el10_1.1.aarch64.rpm corosynclib-3.1.9-2.el10_1.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/corosync-3.1.9-2.el10_1.1.src.rpm Related CVEs: CVE-2026-35091 CVE-2026-35092 Description of changes: [3.1.9-2.1] - Resolves: RHEL-163801 - Resolves: RHEL-163822 - totemsrp: Return error if sanity check fails (fixes CVE-2026-35091) - totemsrp: Fix integer overflow in memb_join_sanity (fixes CVE-2026-35092) _______________________________________________ El-errata mailing list
Two security vulnerabilities were discovered in the Corosync cluster engine, which could result in denial of service or memory disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 3.1.7-1+deb12u2. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6261-1
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-13673 http://linux.oracle.com/errata/ELSA-2026-13673.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: corosync-vqsim-3.1.9-2.el9_7.1.x86_64.rpm corosynclib-3.1.9-2.el9_7.1.i686.rpm corosynclib-3.1.9-2.el9_7.1.x86_64.rpm aarch64: corosync-vqsim-3.1.9-2.el9_7.1.aarch64.rpm corosynclib-3.1.9-2.el9_7.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/corosync-3.1.9-2.el9_7.1.src.rpm Related CVEs: CVE-2026-35091 CVE-2026-35092 Description of changes: [3.1.9-2.1] - Resolves: RHEL-163815 - Resolves: RHEL-163836 - totemsrp: Return error if sanity check fails (fixes CVE-2026-35091) - totemsrp: Fix integer overflow in memb_join_sanity (fixes CVE-2026-35092) _______________________________________________ El-errata mailing list
Moderate: corosync security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:13644", "synopsis": "Moderate: corosync security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for corosync.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The corosync packages provide the Corosync Cluster Engine and C APIs for Rocky Linux cluster software.\n\nSecurity Fix(es):\n\n* corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet (CVE-2026-35091)\n\n* corosync: Corosync: Denial of Service via integer overflow in join message validation (CVE-2026-35092)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2453814", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453814", "description": ""}, {"ticket": "2453813", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453813", "description": ""}], "cves": [{"name": "CVE-2026-35091", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35091", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "cvss3BaseScore": "8.2", "cwe": "CWE-253"}, {"name": "CVE-2026-35092", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35092", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-05-06T12:05:16.751656Z", "rpms": {"Rocky Linux 10": {"nvras": ["corosync-vqsim-debuginfo-0:3.1.9-2.el10_1.1.x86_64.rpm", "corosync-debuginfo-0:3.1.9-2.el10_1.1.s390x.rpm","corosync-vqsim-0:3.1.9-2.el10_1.1.s390x.rpm", "corosynclib-debuginfo-0:3.1.9-2.el10_1.1.s390x.rpm", "corosync-vqsim-0:3.1.9-2.el10_1.1.ppc64le.rpm", "corosync-0:3.1.9-2.el10_1.1.src.rpm", "corosync-debuginfo-0:3.1.9-2.el10_1.1.ppc64le.rpm", "corosynclib-0:3.1.9-2.el10_1.1.s390x.rpm", "corosynclib-0:3.1.9-2.el10_1.1.aarch64.rpm", "corosync-debugsource-0:3.1.9-2.el10_1.1.x86_64.rpm", "corosynclib-debuginfo-0:3.1.9-2.el10_1.1.aarch64.rpm", "corosync-debuginfo-0:3.1.9-2.el10_1.1.aarch64.rpm", "corosynclib-0:3.1.9-2.el10_1.1.ppc64le.rpm", "corosync-vqsim-debuginfo-0:3.1.9-2.el10_1.1.ppc64le.rpm", "corosync-vqsim-debuginfo-0:3.1.9-2.el10_1.1.s390x.rpm", "corosync-debuginfo-0:3.1.9-2.el10_1.1.x86_64.rpm", "corosync-debugsource-0:3.1.9-2.el10_1.1.ppc64le.rpm", "corosync-vqsim-debuginfo-0:3.1.9-2.el10_1.1.aarch64.rpm", "corosynclib-0:3.1.9-2.el10_1.1.x86_64.rpm", "corosync-debugsource-0:3.1.9-2.el10_1.1.aarch64.rpm", "corosync-debugsource-0:3.1.9-2.el10_1.1.s390x.rpm", "corosynclib-debuginfo-0:3.1.9-2.el10_1.1.x86_64.rpm", "corosync-vqsim-0:3.1.9-2.el10_1.1.aarch64.rpm", "corosync-vqsim-0:3.1.9-2.el10_1.1.x86_64.rpm", "corosynclib-debuginfo-0:3.1.9-2.el10_1.1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate security update for corosync affects Rocky Linux 10, fixing potential DoS and information disclosure issues.. Corosync Security Update, Rocky Linux Advisory, DoS Information Disclosure. . LinuxSecurity.com Team
Moderate: corosync security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:13673", "synopsis": "Moderate: corosync security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for corosync.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The corosync packages provide the Corosync Cluster Engine and C APIs for Rocky Linux cluster software.\n\nSecurity Fix(es):\n\n* corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet (CVE-2026-35091)\n\n* corosync: Corosync: Denial of Service via integer overflow in join message validation (CVE-2026-35092)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2453813", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453813", "description": ""}, {"ticket": "2453814", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453814", "description": ""}], "cves": [{"name": "CVE-2026-35091", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35091", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "cvss3BaseScore": "8.2", "cwe": "CWE-253"}, {"name": "CVE-2026-35092", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35092", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-05-06T06:02:14.811706Z", "rpms": {"Rocky Linux 9": {"nvras": ["corosync-0:3.1.9-2.el9_7.1.ppc64le.rpm", "corosync-0:3.1.9-2.el9_7.1.s390x.rpm", "corosync-0:3.1.9-2.el9_7.1.src.rpm","corosync-0:3.1.9-2.el9_7.1.x86_64.rpm", "corosync-debuginfo-0:3.1.9-2.el9_7.1.aarch64.rpm", "corosync-debuginfo-0:3.1.9-2.el9_7.1.i686.rpm", "corosync-debuginfo-0:3.1.9-2.el9_7.1.ppc64le.rpm", "corosync-debuginfo-0:3.1.9-2.el9_7.1.s390x.rpm", "corosync-debuginfo-0:3.1.9-2.el9_7.1.x86_64.rpm", "corosync-debugsource-0:3.1.9-2.el9_7.1.aarch64.rpm", "corosync-debugsource-0:3.1.9-2.el9_7.1.i686.rpm", "corosync-debugsource-0:3.1.9-2.el9_7.1.ppc64le.rpm", "corosync-debugsource-0:3.1.9-2.el9_7.1.s390x.rpm", "corosync-debugsource-0:3.1.9-2.el9_7.1.x86_64.rpm", "corosynclib-0:3.1.9-2.el9_7.1.aarch64.rpm", "corosynclib-0:3.1.9-2.el9_7.1.i686.rpm", "corosynclib-0:3.1.9-2.el9_7.1.ppc64le.rpm", "corosynclib-0:3.1.9-2.el9_7.1.s390x.rpm", "corosynclib-0:3.1.9-2.el9_7.1.x86_64.rpm", "corosynclib-debuginfo-0:3.1.9-2.el9_7.1.aarch64.rpm", "corosynclib-debuginfo-0:3.1.9-2.el9_7.1.i686.rpm", "corosynclib-debuginfo-0:3.1.9-2.el9_7.1.ppc64le.rpm", "corosynclib-debuginfo-0:3.1.9-2.el9_7.1.s390x.rpm", "corosynclib-debuginfo-0:3.1.9-2.el9_7.1.x86_64.rpm", "corosynclib-devel-0:3.1.9-2.el9_7.1.i686.rpm", "corosynclib-devel-0:3.1.9-2.el9_7.1.ppc64le.rpm", "corosynclib-devel-0:3.1.9-2.el9_7.1.s390x.rpm", "corosynclib-devel-0:3.1.9-2.el9_7.1.x86_64.rpm", "corosync-vqsim-0:3.1.9-2.el9_7.1.aarch64.rpm", "corosync-vqsim-0:3.1.9-2.el9_7.1.ppc64le.rpm", "corosync-vqsim-0:3.1.9-2.el9_7.1.s390x.rpm", "corosync-vqsim-0:3.1.9-2.el9_7.1.x86_64.rpm", "corosync-vqsim-debuginfo-0:3.1.9-2.el9_7.1.aarch64.rpm", "corosync-vqsim-debuginfo-0:3.1.9-2.el9_7.1.ppc64le.rpm", "corosync-vqsim-debuginfo-0:3.1.9-2.el9_7.1.s390x.rpm", "corosync-vqsim-debuginfo-0:3.1.9-2.el9_7.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A moderate-security advisory for corosync on Rocky Linux 9, highlighting a critical update needed to address potential threats.. Rocky Linux 9, corosync security update, Denial of Service, information disclosure. . LinuxSecurity.com Team
Moderate: corosync security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:13657", "synopsis": "Moderate: corosync security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for corosync.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The corosync packages provide the Corosync Cluster Engine and C APIs for Rocky Linux cluster software.\n\nSecurity Fix(es):\n\n* corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet (CVE-2026-35091)\n\n* corosync: Corosync: Denial of Service via integer overflow in join message validation (CVE-2026-35092)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2453813", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453813", "description": ""}, {"ticket": "2453814", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2453814", "description": ""}], "cves": [{"name": "CVE-2026-35091", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35091", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "cvss3BaseScore": "8.2", "cwe": "CWE-253"}, {"name": "CVE-2026-35092", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-35092", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-190"}], "references": [], "publishedAt": "2026-05-06T06:00:55.617468Z", "rpms": {"Rocky Linux 8": {"nvras": ["corosync-0:3.1.8-1.el8_10.1.aarch64.rpm", "corosync-0:3.1.8-1.el8_10.1.src.rpm", "corosync-0:3.1.8-1.el8_10.1.x86_64.rpm","corosync-debuginfo-0:3.1.8-1.el8_10.1.aarch64.rpm", "corosync-debuginfo-0:3.1.8-1.el8_10.1.i686.rpm", "corosync-debuginfo-0:3.1.8-1.el8_10.1.x86_64.rpm", "corosync-debugsource-0:3.1.8-1.el8_10.1.aarch64.rpm", "corosync-debugsource-0:3.1.8-1.el8_10.1.i686.rpm", "corosync-debugsource-0:3.1.8-1.el8_10.1.x86_64.rpm", "corosynclib-0:3.1.8-1.el8_10.1.aarch64.rpm", "corosynclib-0:3.1.8-1.el8_10.1.i686.rpm", "corosynclib-0:3.1.8-1.el8_10.1.x86_64.rpm", "corosynclib-debuginfo-0:3.1.8-1.el8_10.1.aarch64.rpm", "corosynclib-debuginfo-0:3.1.8-1.el8_10.1.i686.rpm", "corosynclib-debuginfo-0:3.1.8-1.el8_10.1.x86_64.rpm", "corosynclib-devel-0:3.1.8-1.el8_10.1.aarch64.rpm", "corosynclib-devel-0:3.1.8-1.el8_10.1.i686.rpm", "corosynclib-devel-0:3.1.8-1.el8_10.1.x86_64.rpm", "corosync-vqsim-0:3.1.8-1.el8_10.1.aarch64.rpm", "corosync-vqsim-0:3.1.8-1.el8_10.1.x86_64.rpm", "corosync-vqsim-debuginfo-0:3.1.8-1.el8_10.1.aarch64.rpm", "corosync-vqsim-debuginfo-0:3.1.8-1.el8_10.1.x86_64.rpm", "spausedd-0:3.1.8-1.el8_10.1.aarch64.rpm", "spausedd-0:3.1.8-1.el8_10.1.x86_64.rpm", "spausedd-debuginfo-0:3.1.8-1.el8_10.1.aarch64.rpm", "spausedd-debuginfo-0:3.1.8-1.el8_10.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Corosync security update for Rocky Linux 8 addresses denial of service and information disclosure vulnerabilities effectively.. corosync security update, Rocky Linux patch, DoS threat fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.