CVE-2025-30472

EUVD-2025-7198
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9 CRITICAL
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.44%
Affected Products (NVD)
VendorProductVersion
corosynccorosync
𝑥
≤ 3.1.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
corosync
bookworm
3.1.7-1+deb12u2
fixed
bookworm (security)
3.1.7-1+deb12u2
fixed
forky
3.1.10-4
fixed
sid
3.1.10-4
fixed
trixie
3.1.9-2+deb13u1
fixed
trixie (security)
3.1.9-2+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
corosync
bionic
needs-triage
focal
Fixed 3.0.3-2ubuntu2.2
released
jammy
Fixed 3.1.6-1ubuntu1.1
released
noble
Fixed 3.1.7-1ubuntu3.1
released
oracular
Fixed 3.1.8-2ubuntu1.1
released
plucky
Fixed 3.1.8-3ubuntu2
released
questing
Fixed 3.1.8-3ubuntu2
released
resolute
Fixed 3.1.8-3ubuntu2
released
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
corosync
RHEL 9
0:3.1.9-2.el9_6
fixed
corosync-vqsim
RHEL 9
0:3.1.9-2.el9_6
fixed
corosynclib
RHEL 9
0:3.1.9-2.el9_6
fixed
corosynclib-devel
RHEL 9
0:3.1.9-2.el9_6
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
corosync
Amazon Linux 2
0:2.4.3-6.amzn2.1.1
fixed
corosync-debuginfo
Amazon Linux 2
0:2.4.3-6.amzn2.1.1
fixed
corosync-qdevice
Amazon Linux 2
0:2.4.3-6.amzn2.1.1
fixed
corosync-qnetd
Amazon Linux 2
0:2.4.3-6.amzn2.1.1
fixed
corosynclib
Amazon Linux 2
0:2.4.3-6.amzn2.1.1
fixed
corosynclib-devel
Amazon Linux 2
0:2.4.3-6.amzn2.1.1
fixed
spausedd
Amazon Linux 2
0:2.4.3-6.amzn2.1.1
fixed