{
  "threat_severity" : "Moderate",
  "public_date" : "2025-03-22T00:00:00Z",
  "bugzilla" : {
    "description" : "corosync: Stack buffer overflow from 'orf_token_endian_convert'",
    "id" : "2354229",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2354229"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.6",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-121",
  "details" : [ "Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.", "A flaw was found in Corosync. In affected versions, a stack-based buffer overflow may be triggered via a large UDP packet in configurations where encryption is disabled or if an attacker knows the encryption key. This issue can lead to an application crash or other undefined behavior." ],
  "statement" : "Red Hat believes this vulnerability to be of Moderate impact because successful exploitation requires the attacker to have gained access to the shared secret keys used by the cluster for encrypted communication or for the corosync configuration in the cluster to have encryption and signing disabled, which is a non-standard configuration.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2025-05-13T00:00:00Z",
    "advisory" : "RHSA-2025:7478",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.0",
    "package" : "corosync-0:3.1.9-1.el10_0.1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-05-13T00:00:00Z",
    "advisory" : "RHSA-2025:7201",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "corosync-0:3.1.9-2.el9_6"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Fix deferred",
    "package_name" : "corosync",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "corosync",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-30472\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-30472\nhttps://corosync.org\nhttps://github.com/corosync/corosync/blob/73ba225cc48ebb1903897c792065cb5e876613b0/exec/totemsrp.c#L4677\nhttps://github.com/corosync/corosync/issues/778" ],
  "name" : "CVE-2025-30472",
  "mitigation" : {
    "value" : "To mitigate this vulnerability in RHEL, use pcs to ensure that the corosync configuration used in your cluster(s) has encryption enabled (verify that during setup the `--crypto` option's `cipher` and `hash` parameters are not set to `none`).",
    "lang" : "en:us"
  },
  "csaw" : false
}