Updated corosync and libqb packages fix security vulnerabilities
Publication date: 03 Aug 2026Modification date: 03 Aug 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-35091 , CVE-2026-35092
Description
The updated packages fix security vulnerabilities:
Denial of service and information disclosure via crafted udp packet.
(CVE-2026-35091)
Denial of service via integer overflow in join message validation.
(CVE-2026-35092)
Additionally, libqb solves a missing runtime dependency on qb-blackbox.
References
- https://bugs.mageia.org/show_bug.cgi?id=35431
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XTKM7OVSXAWVNF3FJR76YF55O7VHHZJ7/
- https://lists.debian.org/debian-security-announce/2026/msg00172.html
- https://www.cve.org/CVERecord?id=CVE-2026-35091
- https://www.cve.org/CVERecord?id=CVE-2026-35092
SRPMS
10/core
- corosync-3.1.10-2.1.mga10
- libqb-2.0.9-1.1.mga10
9/core
- corosync-3.1.7-1.3.mga9
- libqb-2.0.8-1.1.mga9