VYPR
High severity8.6NVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026

CVE-2026-10649

CVE-2026-10649

Description

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

14

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.