Unrated severityNVD Advisory· Published Mar 22, 2025· Updated Nov 3, 2025
CVE-2025-30472
CVE-2025-30472
Description
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- osv-coords8 versionspkg:rpm/almalinux/corosynclibpkg:rpm/almalinux/corosync-vqsimpkg:rpm/opensuse/corosync&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/corosync&distro=openSUSE%20Tumbleweedpkg:rpm/suse/corosync&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP3pkg:rpm/suse/corosync&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP4pkg:rpm/suse/corosync&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP5pkg:rpm/suse/corosync&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP6
< 3.1.9-2.el9_6+ 7 more
- (no CPE)range: < 3.1.9-2.el9_6
- (no CPE)range: < 3.1.9-2.el9_6
- (no CPE)range: < 2.4.6-150300.12.13.1
- (no CPE)range: < 3.1.9-2.1
- (no CPE)range: < 2.4.6-150300.12.13.1
- (no CPE)range: < 2.4.6-150300.12.13.1
- (no CPE)range: < 2.4.6-150300.12.13.1
- (no CPE)range: < 2.4.6-150300.12.13.1
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.