mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-05-17 07:59:43 +00:00
Corosync through 3.1.9, if encryption is disabled or the attacker knows
the encryption key, has a stack-based buffer overflow in
orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.
References:
https://nvd.nist.gov/vuln/detail/CVE-2025-30472
Upstream patches:
7839990f9c
Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com>