CVE-2025-30472

EUVD-2025-7198
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9 CRITICAL
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
corosynccorosync
𝑥
≤ 3.1.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
corosync
bookworm
3.1.7-1+deb12u2
fixed
bookworm (security)
3.1.7-1+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
3.1.2-2+deb11u2
fixed
forky
3.1.10-2
fixed
sid
3.1.10-2
fixed
trixie
3.1.9-2+deb13u1
fixed
trixie (security)
3.1.9-2+deb13u1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
corosync
RHEL 9
0:3.1.9-2.el9_6
fixed
corosync-vqsim
RHEL 9
0:3.1.9-2.el9_6
fixed
corosynclib
RHEL 9
0:3.1.9-2.el9_6
fixed
corosynclib-devel
RHEL 9
0:3.1.9-2.el9_6
fixed