CVE-2026-81665: Red Hat Enterprise Linux 10
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 0:3.1.10-1.el10_2.2 (fixed in 0:3.1.10-1.el10_2.2)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 0:3.1.9-1.el10_0.3 (fixed in 0:3.1.9-1.el10_0.3)
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:2.4.5-7.el7_9.4 (fixed in 0:2.4.5-7.el7_9.4)
- Red Hat Red Hat Enterprise Linux 8: before 0:3.1.8-1.el8_10.2 (fixed in 0:3.1.8-1.el8_10.2)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:3.1.0-3.el8_4.3 (fixed in 0:3.1.0-3.el8_4.3)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:3.1.0-3.el8_4.3 (fixed in 0:3.1.0-3.el8_4.3)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:3.1.5-2.el8_6.2 (fixed in 0:3.1.5-2.el8_6.2)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 0:3.1.5-2.el8_6.2 (fixed in 0:3.1.5-2.el8_6.2)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:3.1.7-1.el8_8.2 (fixed in 0:3.1.7-1.el8_8.2)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:3.1.7-1.el8_8.2 (fixed in 0:3.1.7-1.el8_8.2)
- Red Hat Red Hat Enterprise Linux 9: before 0:3.1.10-1.el9_8.2 (fixed in 0:3.1.10-1.el9_8.2)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:3.1.7-1.el9_2.2 (fixed in 0:3.1.7-1.el9_2.2)
- Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:3.1.8-1.el9_4.2 (fixed in 0:3.1.8-1.el9_4.2)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:3.1.9-2.el9_6.2 (fixed in 0:3.1.9-2.el9_6.2)
- Red Hat Red Hat Openshift Container Platform 4
Published 2026-09-04. Last modified 2026-09-30.