Back Linuxsecurity Fedora 45 Corosync Critical Buffer Overflow Fix CVE-2026
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
This package contains the Corosync Cluster Engine Executive, several default
APIs and libraries, default configuration files, and an init script.
Fix CVE-2026-81666 and CVE-2026-81665
* Fri Sep 4 2026 Jan Friesse - 3.1.10-8 - totemsrp: Fix int overflow in commit_token_sanity (fixes CVE-2026-81666) - totempg: Replace assert with check in deliver_fn (fixes CVE-2026-81665)
* Fri Sep 4 2026 Jan Friesse - 3.1.10-8 - totemsrp: Fix int overflow in commit_token_sanity (fixes CVE-2026-81666) - totempg: Replace assert with check in deliver_fn (fixes CVE-2026-81665)
[ 1 ] Bug #2528437 - CVE-2026-81665 corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ef5ca6ecf7' at the command line. For more information, refer to the dnf documentation available at
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
