Skip to content
Fedora 45 Corosync Critical Buffer Overflow Fix CVE-2026

Fedora 45 Corosync Critical Buffer Overflow Fix CVE-2026

Linuxsecurity •LinuxSecurity Advisories • September 11, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

This package contains the Corosync Cluster Engine Executive, several default

APIs and libraries, default configuration files, and an init script.

Fix CVE-2026-81666 and CVE-2026-81665

* Fri Sep 4 2026 Jan Friesse - 3.1.10-8 - totemsrp: Fix int overflow in commit_token_sanity (fixes CVE-2026-81666) - totempg: Replace assert with check in deliver_fn (fixes CVE-2026-81665)

* Fri Sep 4 2026 Jan Friesse - 3.1.10-8 - totemsrp: Fix int overflow in commit_token_sanity (fixes CVE-2026-81666) - totempg: Replace assert with check in deliver_fn (fixes CVE-2026-81665)

[ 1 ] Bug #2528437 - CVE-2026-81665 corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ef5ca6ecf7' at the command line. For more information, refer to the dnf documentation available at

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases