-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 07 May 2026 22:36:24 +0200 Source: corosync Binary: corosync corosync-dbgsym corosync-notifyd corosync-notifyd-dbgsym corosync-vqsim corosync-vqsim-dbgsym libcfg-dev libcfg7 libcfg7-dbgsym libcmap-dev libcmap4 libcmap4-dbgsym libcorosync-common-dev libcorosync-common4 libcorosync-common4-dbgsym libcpg-dev libcpg4 libcpg4-dbgsym libquorum-dev libquorum5 libquorum5-dbgsym libsam-dev libsam4 libsam4-dbgsym libvotequorum-dev libvotequorum8 libvotequorum8-dbgsym Architecture: i386 Version: 3.1.9-2+deb13u1 Distribution: trixie-security Urgency: high Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) Changed-By: Ferenc Wágner Description: corosync - cluster engine daemon and utilities corosync-notifyd - cluster engine notification daemon corosync-vqsim - cluster engine votequorum simulator libcfg-dev - cluster engine CFG library development libcfg7 - cluster engine CFG library libcmap-dev - cluster engine CMAP library development libcmap4 - cluster engine CMAP library libcorosync-common-dev - cluster engine common development libcorosync-common4 - cluster engine common library libcpg-dev - cluster engine CPG library development libcpg4 - cluster engine CPG library libquorum-dev - cluster engine Quorum library development libquorum5 - cluster engine Quorum library libsam-dev - cluster engine SAM library development libsam4 - cluster engine SAM library libvotequorum-dev - cluster engine Votequorum library development libvotequorum8 - cluster engine Votequorum library Closes: 1133837 1133838 Changes: corosync (3.1.9-2+deb13u1) trixie-security; urgency=high . * [128a6c1] New patch: totemsrp: Return error if sanity check fails. Fixes CVE-2026-35091. Thanks to Jan Friesse (Closes: #1133838) * [f46d7eb] New patch: totemsrp: Fix integer overflow in memb_join_sanity. Fixes CVE-2026-35092. Thanks to Jan Friesse (Closes: #1133837) Checksums-Sha1: bf140c5ffa61f96355eace1dffeb6c7e707d1e29 656776 corosync-dbgsym_3.1.9-2+deb13u1_i386.deb 0b130f5e5706e0d91092077b00c1c1f7ae872c94 115752 corosync-notifyd-dbgsym_3.1.9-2+deb13u1_i386.deb fafd3da71855f6d52269965ab7ba3af78b5c2955 271784 corosync-notifyd_3.1.9-2+deb13u1_i386.deb 44c47aa66e11d7da3dd55c32b0e2880868851685 247472 corosync-vqsim-dbgsym_3.1.9-2+deb13u1_i386.deb fd1b5b289ff9a8d74f736dcfd109476590f24b11 313512 corosync-vqsim_3.1.9-2+deb13u1_i386.deb b9ea79527f9a0787400ee15e4bc2e2712a1406c9 15108 corosync_3.1.9-2+deb13u1_i386-buildd.buildinfo 48a7cb8ca819370985d9571814adff71aeaad2a9 503652 corosync_3.1.9-2+deb13u1_i386.deb 516c5b117e8e89ecca7ec3b004141b9b566afc55 257384 libcfg-dev_3.1.9-2+deb13u1_i386.deb 8875b95a68e014bfd56586201e5e182cd1a7ae05 60544 libcfg7-dbgsym_3.1.9-2+deb13u1_i386.deb 46dc01fbd3380b5ebbc656cfa5ed99c7dbb6566d 260856 libcfg7_3.1.9-2+deb13u1_i386.deb ab5cfab081a8cd945aeefe30350e29c7f9224593 289536 libcmap-dev_3.1.9-2+deb13u1_i386.deb 0cb55ea4eeb7e35dd2e6a47b4e5151ff69a9074a 64088 libcmap4-dbgsym_3.1.9-2+deb13u1_i386.deb 0adc21bf3866de9d727b8d0af5ddc4fa9719a276 263144 libcmap4_3.1.9-2+deb13u1_i386.deb 479b146d60b702cd77641eb015407ca7ad297149 257956 libcorosync-common-dev_3.1.9-2+deb13u1_i386.deb 978b658402c7926ec5d99451ad4a42341a2d15b5 20356 libcorosync-common4-dbgsym_3.1.9-2+deb13u1_i386.deb 96eb708f20fbb116a0016a914c685d49a04bed5c 257444 libcorosync-common4_3.1.9-2+deb13u1_i386.deb d9cb389dd8dcadf161a58097d8922a3a4153d888 293748 libcpg-dev_3.1.9-2+deb13u1_i386.deb 8f230c93ca0cb89d20f5fe9bf5a7e0acf4fee3a1 77116 libcpg4-dbgsym_3.1.9-2+deb13u1_i386.deb 8fbc5cf1ea9bdc635e20eef5f4787493e3ba1ef7 263788 libcpg4_3.1.9-2+deb13u1_i386.deb 23103fcb20e1980603b04da9265a7db87d56c551 276036 libquorum-dev_3.1.9-2+deb13u1_i386.deb c0f1feedfaa7a38ca098d6d5f46eb21b1c179dbe 52604 libquorum5-dbgsym_3.1.9-2+deb13u1_i386.deb b3e776de334a86ba407d8efede86191c90c053ca 259608 libquorum5_3.1.9-2+deb13u1_i386.deb 55ebee86c4e7d3df7d345a547574d9b51c8a9018 282528 libsam-dev_3.1.9-2+deb13u1_i386.deb 206ea49f1f9d5245907b54fd5c102ea4ad065a8f 67920 libsam4-dbgsym_3.1.9-2+deb13u1_i386.deb 7a377339289af3c04a1a10a643272819f5525e9a 263300 libsam4_3.1.9-2+deb13u1_i386.deb f593ae394831bf18e92175bb315cffae51aa120d 288048 libvotequorum-dev_3.1.9-2+deb13u1_i386.deb 0e4c04b63b9648ed1c089214f137f5748c61d2f2 55580 libvotequorum8-dbgsym_3.1.9-2+deb13u1_i386.deb e7805db9ce3ca86d9f2e934faa7a3f4792abc60f 260564 libvotequorum8_3.1.9-2+deb13u1_i386.deb Checksums-Sha256: 63b8ab24d62228b10dde782bf630bb26af1289e4ad1c53b5a8b3ead1edbd8066 656776 corosync-dbgsym_3.1.9-2+deb13u1_i386.deb e49efbde0282ef775ef29eb25cb35b83351ce704a03196942b68dbd7f133c42e 115752 corosync-notifyd-dbgsym_3.1.9-2+deb13u1_i386.deb 0beede9c29948cda53b531b18eb6e25ced7f9e610a03cbaa18f8e3e4eeba1bf7 271784 corosync-notifyd_3.1.9-2+deb13u1_i386.deb 89d6b35385437b5fe8b016c49f4ff95c0a9cd607dad832136b1ccf6ebdaf30ad 247472 corosync-vqsim-dbgsym_3.1.9-2+deb13u1_i386.deb 1a74155034792866cde239ee3ccf4bb2c460dd12ba6ae3a298a7a0b27691fdf6 313512 corosync-vqsim_3.1.9-2+deb13u1_i386.deb c4f0b7bdb35f0a03fe91c591b9af2689a20a3ae992ebcf4cc048bb4bfd55a4bf 15108 corosync_3.1.9-2+deb13u1_i386-buildd.buildinfo 671f908c6ba94ead640f2be2dd939b494310b1a47aaf20d551ae894ab1f8ed5c 503652 corosync_3.1.9-2+deb13u1_i386.deb 7443609793d73f22da8a9815f1c5c0eeaf99e9ef5f043ec2d9ac7b47dce06080 257384 libcfg-dev_3.1.9-2+deb13u1_i386.deb 08a542d5644250672c95e83d07442962573be11d7e3cca8cb10ae9b340ec3dab 60544 libcfg7-dbgsym_3.1.9-2+deb13u1_i386.deb b39a35b81217d6f5e65201068361f9c98752c94e36cfa739268a0167f628bcf1 260856 libcfg7_3.1.9-2+deb13u1_i386.deb 64d1ca590361b31ce0fb905d092f16d8a6d249b4559608d2f233c3f1dde86093 289536 libcmap-dev_3.1.9-2+deb13u1_i386.deb caf0a00e6cc50fd12549af7b2264305805743c0c89bd579f073a92451d9ba534 64088 libcmap4-dbgsym_3.1.9-2+deb13u1_i386.deb c95b218287183fc1ee2a88a86e402dc61e30ccfbf335231818d6a0920d649f25 263144 libcmap4_3.1.9-2+deb13u1_i386.deb 196fdaacb65e0fa524b7e3cdabc1d0229632fe1bea88ddf683f69fa9ab8731e7 257956 libcorosync-common-dev_3.1.9-2+deb13u1_i386.deb cc726cca1de3fa3200fd754426846f2d1ded24ffd3762e3638f6f92476017d10 20356 libcorosync-common4-dbgsym_3.1.9-2+deb13u1_i386.deb d22f8d2185a1f2ecf46791bcc5bf49cb7a52afe0744cdfbe061030ab52df6fab 257444 libcorosync-common4_3.1.9-2+deb13u1_i386.deb b065ed251ba3c1161ba54574cdbee233dee7f961a610ba2d265974bb9be4659e 293748 libcpg-dev_3.1.9-2+deb13u1_i386.deb addf1e45da3b89bbffa31f688884e36050aa1da5cf23579d6f4bce6615cb4c83 77116 libcpg4-dbgsym_3.1.9-2+deb13u1_i386.deb 4246eb7152e2631b03a41c4db7d82b7927280277cc93c89ee4c12af988d8abdb 263788 libcpg4_3.1.9-2+deb13u1_i386.deb 70764eaa9961bce8737920581411011b7dab34cda13b8f3c5dfca6e7a821931a 276036 libquorum-dev_3.1.9-2+deb13u1_i386.deb 2951bd008f367ce05b86d7a0d67a5a76ed3740bcf639ff68dd4e93fdbffc0b96 52604 libquorum5-dbgsym_3.1.9-2+deb13u1_i386.deb 1c1bda94a893563f3b6ce82c30fe3b4dea62ff9027ad801e645c3eb1f4d23cd3 259608 libquorum5_3.1.9-2+deb13u1_i386.deb 336a608efca036eb004a0018a8c5c36f00d7249552c0255a5b5fbd3affa4abdf 282528 libsam-dev_3.1.9-2+deb13u1_i386.deb 4a831385da19885555c47b38789909c145383fa26a7ae6f932eb84ed9d4e4143 67920 libsam4-dbgsym_3.1.9-2+deb13u1_i386.deb e5dcd1043b54767251b4fde52bab93cbcdecdd36da763afa287beb897bdc3be5 263300 libsam4_3.1.9-2+deb13u1_i386.deb 7c03b8cee65645e0238d8e6342fb0deb5f1942f06016dd5c3f15eaf163187bc5 288048 libvotequorum-dev_3.1.9-2+deb13u1_i386.deb 26df8246f903a943962f97b0cce21a364241d5871799f1fdd5dd8ccc0b08dd0e 55580 libvotequorum8-dbgsym_3.1.9-2+deb13u1_i386.deb e0bed20b4720e8f0120704ca754284654b3bce9e172b042436a1f0f8936642b6 260564 libvotequorum8_3.1.9-2+deb13u1_i386.deb Files: d97673ee150d75cc2f5e4ac71827d3ea 656776 debug optional corosync-dbgsym_3.1.9-2+deb13u1_i386.deb fd381efdf9305c9a09d0391ced354a36 115752 debug optional corosync-notifyd-dbgsym_3.1.9-2+deb13u1_i386.deb af0eb1e0d8b49fd76dcaeac322bd917a 271784 admin optional corosync-notifyd_3.1.9-2+deb13u1_i386.deb ae8084eba58b1241ea8e38d7e95d2747 247472 debug optional corosync-vqsim-dbgsym_3.1.9-2+deb13u1_i386.deb a3d0a09ecf5ab20d6a3645e782aaf0ab 313512 admin optional corosync-vqsim_3.1.9-2+deb13u1_i386.deb 8abeb64574fc6720a989b8281bcfe19f 15108 admin optional corosync_3.1.9-2+deb13u1_i386-buildd.buildinfo 7f3a1dccb602f458a366ea8dd686c880 503652 admin optional corosync_3.1.9-2+deb13u1_i386.deb 1f738f2747aed855c10b5ddf45ad97f4 257384 libdevel optional libcfg-dev_3.1.9-2+deb13u1_i386.deb f47286518d59490423c0b44531f74627 60544 debug optional libcfg7-dbgsym_3.1.9-2+deb13u1_i386.deb 235acbcfb344d21fab27b59ff32a30bd 260856 libs optional libcfg7_3.1.9-2+deb13u1_i386.deb d299099882c424c70919ca09c4fbfd9a 289536 libdevel optional libcmap-dev_3.1.9-2+deb13u1_i386.deb c5411c20885fa23a0ce935e14f03e7a9 64088 debug optional libcmap4-dbgsym_3.1.9-2+deb13u1_i386.deb 7c82532358675340574a89e0afdcb0fd 263144 libs optional libcmap4_3.1.9-2+deb13u1_i386.deb 4a0f16410d4db922ca6232779a934328 257956 libdevel optional libcorosync-common-dev_3.1.9-2+deb13u1_i386.deb 46669e5b65a669d347e63c9c8daa4c87 20356 debug optional libcorosync-common4-dbgsym_3.1.9-2+deb13u1_i386.deb 1049077e0576af5337ac481b95f98308 257444 libs optional libcorosync-common4_3.1.9-2+deb13u1_i386.deb 051b6f41c3a175c977e2de0c013b6f96 293748 libdevel optional libcpg-dev_3.1.9-2+deb13u1_i386.deb 1ee9f9b8e2b6ae62880c4578935b08f4 77116 debug optional libcpg4-dbgsym_3.1.9-2+deb13u1_i386.deb 38ac5f6ea7f8d786963c3a06992139d2 263788 libs optional libcpg4_3.1.9-2+deb13u1_i386.deb f103bd2329a604a53cdb63c7568af5d4 276036 libdevel optional libquorum-dev_3.1.9-2+deb13u1_i386.deb d5e0ec77326087e2fc9e7410a1c40f04 52604 debug optional libquorum5-dbgsym_3.1.9-2+deb13u1_i386.deb d94b2655a78aea3ddbb095a3bbe06e73 259608 libs optional libquorum5_3.1.9-2+deb13u1_i386.deb 6f3c9d330c4b80f253e0c6d084e1c19b 282528 libdevel optional libsam-dev_3.1.9-2+deb13u1_i386.deb f1e86a12f66835dc3cc26e2d80992c87 67920 debug optional libsam4-dbgsym_3.1.9-2+deb13u1_i386.deb de0dbad7c909d6703001049455a2b640 263300 libs optional libsam4_3.1.9-2+deb13u1_i386.deb 16c0caec737f4c86abe57ec969af511d 288048 libdevel optional libvotequorum-dev_3.1.9-2+deb13u1_i386.deb f87b6872d97e98b19663bcefdadcae1c 55580 debug optional libvotequorum8-dbgsym_3.1.9-2+deb13u1_i386.deb f06feba23acbc2fbe7b218fb7e5b833f 260564 libs optional libvotequorum8_3.1.9-2+deb13u1_i386.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE+i/sCsF3puL4e7qIGNGWmfrqILEFAmn+O58ACgkQGNGWmfrq ILEQig/+LaQQhNn5z7rUhywpQtfElVz8mBIGQk0aN4o4wEkKX/mPNq4I22IBaTwZ IBpumJZvIqjafSeoXTi/9q7t/TxvPJMe4SaVVg8lNneJp86CFiFIs+0tuv95jT6r Nnh+s26ZrJi9rQOgaa/Kkmc6Xqm0jSMR2liNMIB3PSXOpBVk0jlhfEbbG0mTqGJQ j7DqukkNEkQbxKneV0M0RMPjxmDVBE2xPafAINLaWpNC0wuoRtnqntkSOrAOwoTO 1ZK3OI0uCgnH5/7W60epHaFyiRFapV0pH8lkr6H31uXcZ7Ik0RBxEaWbxJi89JIe i4OfLKvk4qqSxgQXm8nbdxgjN19C05DMWkkx7yO8sqVEuOy8TVdQ2RnQAgk7UkbN sPfxY5camH7I4F3eQH31TIHb9loBbdhtz7ktFV0JqbY+xqJa4OCfeaIotUEkHGrx gqo/Dp6awJbthHGoWacCrq9bebdvvSpmN/18aGEmMnYlDIfdQx/F437Lbu0rEk7k PNbsr0v6bAprZHWlok4YW3CB/xYgvnKw4KkiYUOoYNmPCWQmKsH+BgWuxlI0yME9 wPR8fcLZaoXzR6aLIrrd0M+y/z+Lc4OYxXCZ8THMHTsFowoHKefHxc1ziRJSussW NSjzpQywY0PDY6xl3debHF64SOV7CNNnGqWRe46ceVHjpWA8EFg= =hTX5 -----END PGP SIGNATURE-----