PT-2026-49723 · Pacemaker+1 · Pacemaker+1

·

CVE-2026-10649

·

Published

2026-06-16

·

Updated

2026-07-20

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Pacemaker (affected versions not specified)
Description An integer overflow exists in the remote message decompression process. An unauthenticated remote attacker can exploit this by sending a specially crafted compressed remote message before authentication, causing memory corruption. This leads to a denial of service (DoS) in the CIB remote listener, resulting in the affected service crashing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:39322
ALSA-2026:39323
CVE-2026-10649
OESA-2026-2937
OESA-2026-2938
OESA-2026-2989
OESA-2026-2990
OESA-2026-2991
OPENSUSE-SU-2026:11111-1
OPENSUSE-SU-2026:21196-1
RHSA-2026:39322
RHSA-2026:39323
RHSA-2026:40833
RHSA-2026:41041
RHSA-2026:41042
RHSA-2026:41043
RHSA-2026:41044
SUSE-SU-2026:22493-1
SUSE-SU-2026:22510-1
SUSE-SU-2026:2701-1
SUSE-SU-2026:2716-1
SUSE-SU-2026:2719-1
SUSE-SU-2026:2742-1
SUSE-SU-2026:2970-1

Affected Products

Pacemaker
Rocky Linux