CVE-2025-30472

Published Mar 22, 2025

Last updated 3 months ago

Overview

Description
Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet.
Source
cve@mitre.org
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cve@mitre.org
CWE-121
nvd@nist.gov
CWE-787

Social media

Hype score
Not currently trending
  1. Critical Alert: Corosync flaw (CVE-2025-30472) impacts Ubuntu 20.04–24.10—patch now to prevent cluster crashes! ▶ Exploit details & fixes:👉 https://t.co/wmijIHC3ED #Security #Ubuntu https://t.co/CWXgNSN2v9

    @Cezar_H_Linux

    5 May 2025

    49 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2025-30472: Critical buffer overflow in Corosync (≤3.1.9). CVSS 9.0. 🔒 No encryption? At risk! Details: https://t.co/0rw0P5A0kx #Cybersecurity #Tech #Cve https://t.co/233no0VYQm

    @threatsbank

    24 Mar 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2025-30472 ⚠️🔴 CRITICAL (9) 🏢 Corosync - Corosync 🏗️ 0 🔗 https://t.co/Coj1GrexhI 🔗 https://t.co/roUFEBwHi3 🔗 https://t.co/jSrpgC0Lai #CyberCron #VulnAlert #InfoSec https://t.co/PoD20Q1nv6

    @cybercronai

    23 Mar 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-30472 Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/tote… https://t.co/agFjLxiIvX

    @CVEnew

    22 Mar 2025

    338 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. [CVE-2025-30472: CRITICAL] Corosync is vulnerable to a stack-based buffer overflow allowing attackers to exploit the system via large UDP packets if encryption is disabled or key is known.#cybersecurity,#vulnerability https://t.co/xm606w13G2 https://t.co/f6EoWPJImG

    @CveFindCom

    22 Mar 2025

    29 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations