Security Advisory

CVE-2026-10649

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-16 15:57:38
Last updated 2026-07-23 12:08:07
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.