[USN-7478-1] Corosync vulnerability

Marc Deslauriers marc.deslauriers at canonical.com
Mon May 5 14:04:13 UTC 2025


==========================================================================
Ubuntu Security Notice USN-7478-1
May 05, 2025

corosync vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 24.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS

Summary:

Corosync could be made to crash if it received specially crafted network
traffic.

Software Description:
- corosync: cluster engine daemon and utilities

Details:

It was discovered that Corosync incorrectly handled certain large UDP
packets. If encryption is disabled, or an attacker knows the encryption
key, this issue could be used to cause Corosync to crash, resulting in a
denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.10
   corosync                        3.1.8-2ubuntu1.1

Ubuntu 24.04 LTS
   corosync                        3.1.7-1ubuntu3.1

Ubuntu 22.04 LTS
   corosync                        3.1.6-1ubuntu1.1

Ubuntu 20.04 LTS
   corosync                        3.0.3-2ubuntu2.2

After a standard system update you need to restart Corosync to make all the
necessary changes.

References:
   https://ubuntu.com/security/notices/USN-7478-1
   CVE-2025-30472

Package Information:
   https://launchpad.net/ubuntu/+source/corosync/3.1.8-2ubuntu1.1
   https://launchpad.net/ubuntu/+source/corosync/3.1.7-1ubuntu3.1
   https://launchpad.net/ubuntu/+source/corosync/3.1.6-1ubuntu1.1
   https://launchpad.net/ubuntu/+source/corosync/3.0.3-2ubuntu2.2

-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/ubuntu-security-announce/attachments/20250505/8a41adbd/attachment.sig>


More information about the ubuntu-security-announce mailing list