The manufacturer Canonical has not yet set up its devicebase profile. Content such as updates, compatibilities and support may only be maintained with a delay.
Update

USN-7478-1: Corosync vulnerability

USN-7478-1: Corosync vulnerability
5 May 2025

Corosync could be made to crash if it received specially crafted network traffic.

Releases

  • Ubuntu 24.10
  • Ubuntu 24.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 ESM

Packages
corosync - cluster engine daemon and utilities

Details
It was discovered that Corosync incorrectly handled certain large UDP
packets. If encryption is disabled, or an attacker knows the encryption
key, this issue could be used to cause Corosync to crash, resulting in a
denial of service.

Update instructions
The problem can be corrected by updating your system to the following package versions:

Ubuntu 24.10

  • corosync - 3.1.8-2ubuntu1.1
    Ubuntu 24.04
  • corosync - 3.1.7-1ubuntu3.1
    Ubuntu 22.04
  • corosync - 3.1.6-1ubuntu1.1
    Ubuntu 20.04
  • corosync - 3.0.3-2ubuntu2.2
    After a standard system update you need to restart Corosync to make all the
    necessary changes.
Version: Ubuntu 24.04 LTS Link
Receive Important Update Messages Stay tuned for upcoming Canonical Ubuntu Desktop updates

More from the Operating Systems section

Was the content helpful to you?

Advertisement Advertise here?
Udemy IT certification ad