corosync: Denial of service A vulnerability in corosync could lead to a Denial of Service condition. corosync 2021-07-03 2021-07-03 658354 remote 3.0.4 3.0.4

The Corosync Cluster Engine is a Group Communication System with additional features for implementing high availability within applications.

It was discovered that corosync allowed an unauthenticated user to cause a Denial of Service by application crash.

A remote attacker could send a malicious crafted packet, possibly resulting in a Denial of Service condition.

There is no known workaround at this time.

All corosync users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=sys-cluster/corosync-3.0.4"
CVE-2018-1084 whissi whissi