Impact
An integer overflow in Corosync’s calculation of the expected membership commit token message length can bypass the message-length validation on 32‑bit systems. A crafted packet crafted to exploit this overflow triggers an out‑of‑bounds memory access that crashes the Corosync daemon, causing the affected cluster node to stop responding to requests.
Affected Systems
The flaw is present in Red Hat Enterprise Linux 10, 7, 8, and 9, as well as Red Hat OpenShift Container Platform 4. The vulnerability only affects 32‑bit deployments; on 64‑bit systems the length calculation is performed with 64‑bit arithmetic and the overflow does not occur.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers with network access to the cluster communication ports (5405‑5412/UDP) may send a malicious membership commit token message; the likely attack vector is network‑based intrusion to the cluster nodes. Exploitation would result in a denial of service on the targeted node, potentially disrupting cluster availability.
OpenCVE Enrichment