ALSA-2026:13657

Source
https://errata.almalinux.org/8/ALSA-2026-13657.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:13657.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALSA-2026:13657
Related
  • CVE-2026-35091
  • CVE-2026-35092
Published
2026-05-05T00:00:00Z
Modified
2026-05-06T10:30:10.904332Z
Summary
Moderate: corosync security update
Details

The corosync packages provide the Corosync Cluster Engine and C APIs for AlmaLinux cluster software.

Security Fix(es):

  • corosync: Corosync: Denial of Service and information disclosure via crafted UDP packet (CVE-2026-35091)
  • corosync: Corosync: Denial of Service via integer overflow in join message validation (CVE-2026-35092)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:8 / corosync

Package

Name
corosync
Purl
pkg:rpm/almalinux/corosync

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.8-1.el8_10.1

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:13657.json"

AlmaLinux:8 / corosync-vqsim

Package

Name
corosync-vqsim
Purl
pkg:rpm/almalinux/corosync-vqsim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.8-1.el8_10.1

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:13657.json"

AlmaLinux:8 / corosynclib

Package

Name
corosynclib
Purl
pkg:rpm/almalinux/corosynclib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.8-1.el8_10.1

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:13657.json"

AlmaLinux:8 / corosynclib-devel

Package

Name
corosynclib-devel
Purl
pkg:rpm/almalinux/corosynclib-devel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.8-1.el8_10.1

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:13657.json"

AlmaLinux:8 / spausedd

Package

Name
spausedd
Purl
pkg:rpm/almalinux/spausedd

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.8-1.el8_10.1

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:13657.json"