High severity8.6NVD Advisory· Published Jun 16, 2026· Updated Aug 21, 2026
CVE-2026-10649
CVE-2026-10649
Description
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15(expand)+ 1 more
- (no CPE)
- (no CPE)
- osv-coords13 versionspkg:rpm/almalinux/pacemakerpkg:rpm/almalinux/pacemaker-clipkg:rpm/almalinux/pacemaker-cluster-libspkg:rpm/almalinux/pacemaker-ctspkg:rpm/almalinux/pacemaker-docpkg:rpm/almalinux/pacemaker-libspkg:rpm/almalinux/pacemaker-libs-develpkg:rpm/almalinux/pacemaker-nagios-plugins-metadatapkg:rpm/almalinux/pacemaker-remotepkg:rpm/almalinux/pacemaker-schemaspkg:rpm/almalinux/python3-pacemakerpkg:rpm/opensuse/pacemaker&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/pacemaker&distro=openSUSE%20Tumbleweed
< 2.1.7-5.6.el8_10+ 12 more
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 3.0.0+20250218.64cd85422c-160000.4.1
- (no CPE)range: < 3.0.2+20260616.4544f351-1.1
Patches
Vulnerability mechanics
References
16- www.openwall.com/lists/oss-security/2026/06/16/6nvd
- access.redhat.com/errata/RHSA-2026:39322nvd
- access.redhat.com/errata/RHSA-2026:39323nvd
- access.redhat.com/errata/RHSA-2026:40833nvd
- access.redhat.com/errata/RHSA-2026:41041nvd
- access.redhat.com/errata/RHSA-2026:41042nvd
- access.redhat.com/errata/RHSA-2026:41043nvd
- access.redhat.com/errata/RHSA-2026:41044nvd
- access.redhat.com/errata/RHSA-2026:42041nvd
- access.redhat.com/errata/RHSA-2026:42075nvd
- access.redhat.com/errata/RHSA-2026:42076nvd
- access.redhat.com/errata/RHSA-2026:43606nvd
- access.redhat.com/security/cve/CVE-2026-10649nvd
- bugzilla.redhat.com/show_bug.cginvd
- github.com/clusterLabs/pacemaker/pull/4128nvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10649.jsonnvd
News mentions
0No linked articles in our index yet.