Skip to content

fix(corosync): pin-forward to f43 for 2 CVEs#17279

Draft
tobiasb-ms wants to merge 1 commit into
tomls/base/mainfrom
tobiasb-ms/cve-fix-corosync
Draft

fix(corosync): pin-forward to f43 for 2 CVEs#17279
tobiasb-ms wants to merge 1 commit into
tomls/base/mainfrom
tobiasb-ms/cve-fix-corosync

Conversation

@tobiasb-ms
Copy link
Copy Markdown
Contributor

CVE Pin-Forward: corosync

Pins corosync to Fedora f43 HEAD (63ea76e) to pick up
2 CVE patches added upstream.

CVEs Resolved

CVE Severity Status
CVE-2026-35091 High Tracked
CVE-2026-35092 High Tracked

Fedora Spec Delta

Old commit: 2de47be
New commit: 63ea76e

New patches:

  • 0001-totemsrp-Return-error-if-sanity-check-fails.patch
  • 0002-totemsrp-Fix-integer-overflow-in-memb_join_sanity.patch

Pin locks/corosync.lock to Fedora f43 HEAD to pick up
CVE-specific patches added upstream.

CVEs resolved (2 tracked, 0 additional):

  Tracked:
    CVE-2026-35091 (High)
    CVE-2026-35092 (High)

Fedora f43 spec delta (2de47be..63ea76e):
  + 0001-totemsrp-Return-error-if-sanity-check-fails.patch
  + 0002-totemsrp-Fix-integer-overflow-in-memb_join_sanity.patch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant