Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-30472


Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.


Published

2025-03-22T02:15:16.620

Last Modified

2025-11-03T19:15:49.987

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.0 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-121
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application corosync corosync ≤ 3.1.9 Yes

References