A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-81665 represents a critical vulnerability in Corosync's Totem Process Group (totempg) message reassembly logic, where fragmented multicast messages are processed without proper runtime bounds checking in release builds. This heap-based buffer overflow allows network-adjacent attackers to inject crafted multicast protocol messages that corrupt heap memory with attacker-controlled data. Organizations running Corosync for high-availability clustering—including Red Hat Enterprise Linux clusters, Kubernetes infrastructure, and distributed database systems—face immediate risk of denial of service when this vulnerability is exploited, potentially taking entire cluster infrastructures offline.
While MITRE ATT&CK mapping is not yet available for this CVE, Casky's 754 security skills and Claude AI's extended reasoning enable detection of the attack patterns underlying this vulnerability. Practitioners using Casky would identify suspicious indicators including abnormal multicast traffic patterns with fragmented messages, unexpected heap memory corruption signatures in Corosync daemon logs, and process crashes tied to specific message sequence patterns. The platform's skill set would correlate these technical indicators with resource exhaustion and process termination behaviors, allowing security teams to detect exploitation attempts before cluster-wide denial of service occurs. Casky's analysis would help practitioners distinguish between legitimate fragmented multicast reassembly and malicious packet crafting attempts targeting the bounds-checking gap.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-81665. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation