High severity8.6NVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026
CVE-2026-10649
CVE-2026-10649
Description
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14- osv-coords12 versionspkg:rpm/almalinux/pacemakerpkg:rpm/almalinux/pacemaker-clipkg:rpm/almalinux/pacemaker-cluster-libspkg:rpm/almalinux/pacemaker-ctspkg:rpm/almalinux/pacemaker-docpkg:rpm/almalinux/pacemaker-libspkg:rpm/almalinux/pacemaker-libs-develpkg:rpm/almalinux/pacemaker-nagios-plugins-metadatapkg:rpm/almalinux/pacemaker-remotepkg:rpm/almalinux/pacemaker-schemaspkg:rpm/almalinux/python3-pacemakerpkg:rpm/opensuse/pacemaker&distro=openSUSE%20Tumbleweed
< 2.1.7-5.6.el8_10+ 11 more
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 2.1.7-5.6.el8_10
- (no CPE)range: < 3.0.2+20260616.4544f351-1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.