Amazon Linux 2023 Security Advisory: ALAS2023-2026-3138
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control. (CVE-2026-81665)
Affected Packages:
corosync
Issue Correction:
Run dnf update corosync --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3138 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
corosync-debuginfo-3.1.9-3.amzn2023.0.3.aarch64
corosync-3.1.9-3.amzn2023.0.3.aarch64
corosync-vqsim-debuginfo-3.1.9-3.amzn2023.0.3.aarch64
corosync-vqsim-3.1.9-3.amzn2023.0.3.aarch64
corosynclib-3.1.9-3.amzn2023.0.3.aarch64
corosync-debugsource-3.1.9-3.amzn2023.0.3.aarch64
corosynclib-debuginfo-3.1.9-3.amzn2023.0.3.aarch64
corosynclib-devel-3.1.9-3.amzn2023.0.3.aarch64
src:
corosync-3.1.9-3.amzn2023.0.3.src
x86_64:
corosync-debugsource-3.1.9-3.amzn2023.0.3.x86_64
corosynclib-devel-3.1.9-3.amzn2023.0.3.x86_64
corosync-vqsim-debuginfo-3.1.9-3.amzn2023.0.3.x86_64
corosync-vqsim-3.1.9-3.amzn2023.0.3.x86_64
corosynclib-debuginfo-3.1.9-3.amzn2023.0.3.x86_64
corosynclib-3.1.9-3.amzn2023.0.3.x86_64
corosync-debuginfo-3.1.9-3.amzn2023.0.3.x86_64
corosync-3.1.9-3.amzn2023.0.3.x86_64