|
|
Subscribe / Log in / New account

Ubuntu alert USN-7478-1 (corosync)

From:  Marc Deslauriers <marc.deslauriers@canonical.com>
To:  "ubuntu-security-announce@lists.ubuntu.com" <ubuntu-security-announce@lists.ubuntu.com>
Subject:  [USN-7478-1] Corosync vulnerability
Date:  Mon, 05 May 2025 10:04:13 -0400
Message-ID:  <3dabeaf1-5853-4970-8c78-f3ee9024ef26@canonical.com>

========================================================================== Ubuntu Security Notice USN-7478-1 May 05, 2025 corosync vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Corosync could be made to crash if it received specially crafted network traffic. Software Description: - corosync: cluster engine daemon and utilities Details: It was discovered that Corosync incorrectly handled certain large UDP packets. If encryption is disabled, or an attacker knows the encryption key, this issue could be used to cause Corosync to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 corosync 3.1.8-2ubuntu1.1 Ubuntu 24.04 LTS corosync 3.1.7-1ubuntu3.1 Ubuntu 22.04 LTS corosync 3.1.6-1ubuntu1.1 Ubuntu 20.04 LTS corosync 3.0.3-2ubuntu2.2 After a standard system update you need to restart Corosync to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7478-1 CVE-2025-30472 Package Information: https://launchpad.net/ubuntu/+source/corosync/3.1.8-2ubun... https://launchpad.net/ubuntu/+source/corosync/3.1.7-1ubun... https://launchpad.net/ubuntu/+source/corosync/3.1.6-1ubun... https://launchpad.net/ubuntu/+source/corosync/3.0.3-2ubun...


Attachment: OpenPGP_signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAmgYxV0FAwAAAAAACgkQZWnYVadEvpOC 1xAAka3XhlZ8C/LkI7mozDH/6uKPMl+Zb8ZuWaX/ZY5Xvhp78Reb1kYY8mJm6qcJde7/UsWtwfZh 9VjCXLJ3HmPbnzCQ9pfM7yVV9FbaVj6P9awZoSKEXru4Whl772qpCQsGt9riYoHCGwB56VyitkaD gjgupdMw3xdevWuK2xn3I6EF7a58HjvmaSIPMRaBeF9qhtRiXO6ljyz6N9WruMKJnv9TPceI1c0F t9VSVgtmrtAOfYEZ0MtzxY+p8NTXkwI8PdTWGYqwuqRUInDqDyHShR0eQk5Xhj90R9L8Tq0nFX2v mpOD4gosV9VBynAG7IHV1K+HtQRX4Yi/BuP/w2e7ULF+1AOrytLuh6aL+m5F0edjXNvynVmEGwt2 P3PSUiMtDTawmeNuETfDsoS6WmXPjeoGF9GbXdys9UtYA6vqrad5Pceccl9GVE+8kzELvgkGWO8e xTK5IJu0i15wBa+NOBI4QQXFIHAPjA8lXXxsGFH4Iu7eKDvap92DI0m9ajX3S3SpJFA7viqvbCx+ 8xwRI72+fbXRJS+5izko+v2ZpUnB7+lasPyJLUNcuAdJirAbtBuT44tS9SNFF2LKwl4ghSEQuL9G pLCREsHzX8mKQGpS5V3O8hXfa6vlwk8Wr6Qd7D9kxPOWTZ++xvyWcjHAK4C5Z3YVRSZnQSR7Wcc7 xdY= =Ntk9 -----END PGP SIGNATURE-----


Attachment: None (type=text/plain)


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds