
CVE-2026-10649: Pacemaker: DoS via integer overflow in remote message decompression https://www.openwall.com/lists/oss-security/2026/06/16/6 By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption. Impact beyond DoS not ruled out.
Post summary
The text announces CVE-2026-10649, detailing an integer-overflow vulnerability in Pacemaker’s message decompression that can lead to memory corruption and DoS, with no evidence of active exploitation or available patches.



