Skip to content
Red HatCVE-2026-81666

Red Hat Enterprise Linux 10: integer overflow

Medium6.5CVE-2026-81666 · Published Sep 4, 2026 · updated Sep 8, 2026

An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory access that crashes the Corosync daemon. This results in a denial of service for the affected cluster node. The overflow does not occur on 64-bit systems, where the length calculation is correctly performed in 64-bit arithmetic.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-190

More Red Hat advisories

All Red Hat
Advisory
Red Hat Flatpak: race condition
Medium5.8Sep 4
Red Hat libtpms: denial of service
Medium6.5Sep 4
Red Hat libsoup.: reachable assertion
Medium5.9Sep 4
Red Hat: heap buffer overflow
High7.5Sep 4
Red Hat libsoup: use after free
High7.6Sep 4
Red Hat Ansible Automation Platform 2: improper signature check
Medium5.9Sep 3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.