Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-10649

HIGH NVD
CVSS Score 8.6
Severity HIGH
Published Jun 16, 2026
Vendor unknown

Description

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.

References