Skip to content

fix(corosync): CVE-2025-30472#3

Open
deepin-ci-robot wants to merge 2 commits intomasterfrom
fix/CVE-2025-30472-v2
Open

fix(corosync): CVE-2025-30472#3
deepin-ci-robot wants to merge 2 commits intomasterfrom
fix/CVE-2025-30472-v2

Conversation

@deepin-ci-robot
Copy link
Copy Markdown
Contributor

CVE 修复

CVE ID: CVE-2025-30472

漏洞描述: Corosync through 3.1.9 has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet. If encryption is disabled or the attacker knows the encryption key, this can lead to crash of corosync or potentially arbitrary code execution.

修复方案: Patch (backport upstream fix)

  • Added size check for orf_token message before endian conversion
  • Added validation for rtr_entries to prevent corruption
  • Prevents buffer overflow from carefully crafted malicious UDP packets

受影响版本: corosync <= 3.1.9

当前版本: 3.1.5-2

验证状态: ✅ Patch tested and applies cleanly

上游修复: corosync/corosync@7839990


Fix-Approach: patch (backport upstream commit)
Generated-By: CVE-Fixer Agent
Co-Authored-By: hudeng hudeng@deepin.org

- Added size check for orf_token message before endian conversion
- Added validation for rtr_entries to prevent corruption
- Prevents stack-based buffer overflow from malicious UDP packets

Fix-Approach: patch (backport upstream commit)
Upstream: corosync/corosync@7839990
CVE: CVE-2025-30472

Generated-By: CVE-Fixer Agent
Co-Authored-By: hudeng <hudeng@deepin.org>
@deepin-ci-robot deepin-ci-robot requested a review from BLumia May 9, 2026 02:27
@deepin-ci-robot
Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign zccrs for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 9, 2026

TAG Bot

TAG: 3.1.5-3
EXISTED: no
DISTRIBUTION: unstable

Adjust patch line numbers to match current source code version (3.1.5-2).
The previous patch had incorrect line numbers causing apply failures.

Generated-By: glm-5.1
Co-Authored-By: hudeng <hudeng@deepin.org>
@hudeng-go
Copy link
Copy Markdown

/integrate

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 9, 2026

AutoIntegrationPr Bot
auto integrate with pr url: deepin-community/Repository-Integration#3971
PrNumber: 3971
PrBranch: auto-integration-25590057767

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants