Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-81665
Red Hat Red Hat Enterprise Linux 10 — Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly
AV AC PR UI S C I A CVSS EPSS %ile KEV
A H N N U H H H 7.5 .0035 26.2 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 10 unspecified 0:3.1.10-1.el10_2.2
Red Hat Enterprise Linux 10.0 Extended Update Support unspecified 0:3.1.9-1.el10_0.3
Red Hat Enterprise Linux 7 Extended Lifecycle Support unspecified 0:2.4.5-7.el7_9.4
Red Hat Enterprise Linux 8 unspecified 0:3.1.8-1.el8_10.2
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support unspecified 0:3.1.0-3.el8_4.3
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On unspecified 0:3.1.0-3.el8_4.3
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support unspecified 0:3.1.5-2.el8_6.2
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On unspecified 0:3.1.5-2.el8_6.2
Red Hat Enterprise Linux 8.8 Telecommunications Update Service unspecified 0:3.1.7-1.el8_8.2
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions unspecified 0:3.1.7-1.el8_8.2
+ 6 more
TIMELINE
Aug 27 Reserved by redhat
Sep 4 Published (CNA: redhat)
Sep 16 PATCH SHIPPED — CVE-2026-81665 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:3.1.10-1.el10_2.2.
Description
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 27, 2026 | Reserved | Reserved by redhat |
| September 4, 2026 | Published | Published (CNA: redhat) |
| September 16, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-81665 (Red Hat Enterprise Linux 10). Fixed in Red Hat Enterprise Linux 10 0:3.1.10-1.el10_2.2. |
Affected
Affected products and packages — 16 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | 0:3.1.10-1.el10_2.2 |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | — | — | 0:3.1.9-1.el10_0.3 |
| Red Hat | Red Hat Enterprise Linux 7 Extended Lifecycle Support | — | — | 0:2.4.5-7.el7_9.4 |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | 0:3.1.8-1.el8_10.2 |
| Red Hat | Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | — | — | 0:3.1.0-3.el8_4.3 |
| Red Hat | Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | — | — | 0:3.1.0-3.el8_4.3 |
| Red Hat | Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | — | — | 0:3.1.5-2.el8_6.2 |
| Red Hat | Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On | — | — | 0:3.1.5-2.el8_6.2 |
| Red Hat | Red Hat Enterprise Linux 8.8 Telecommunications Update Service | — | — | 0:3.1.7-1.el8_8.2 |
| Red Hat | Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | — | — | 0:3.1.7-1.el8_8.2 |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 0:3.1.10-1.el9_8.2 |
| Red Hat | Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | — | — | 0:3.1.7-1.el9_2.2 |
| Red Hat | Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions | — | — | 0:3.1.8-1.el9_4.2 |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | — | — | 0:3.1.9-2.el9_6.2 |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
| Red Hat | Red Hat OpenShift Container Platform 4 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-81665 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.