Red Hat disclosed CVE-2026-10649, an Important-severity flaw in Pacemaker that can let an unauthenticated remote attacker crash the service by sending a crafted compressed message to the CIB remote listener. The bug is an integer overflow in remote message decompression in lib/common/remote.c, specifically pcmk__remote_message_xml(), where attacker-controlled header fields are used in size calculations before allocation, creating a pre-authentication path to memory corruption and denial of service. The issue is reachable over the network when remote-port or remote-tls-port is enabled; in TLS deployments, an attacker must first complete the GnuTLS handshake.
ClusterLabs published upstream fixes in pull request #4128, adding stricter header validation, overflow-safe arithmetic, corrected size checks, clearer error handling, and a 20 MB cap on remote message size to prevent crashes, memory corruption, and unbounded memory allocation that could also contribute to node fencing. Maintainers noted Pacemaker has not used its remote message compression code since it was introduced in 2013, which may explain why the defect went unnoticed. Until patched builds are deployed, defenders are advised to disable the CIB remote listener if it is not needed or restrict access to trusted peers only.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat Product Security disclosed CVE-2026-10649 on the oss-sec mailing list, describing an Important-severity Pacemaker flaw that allows unauthenticated remote denial of service through integer overflow in pre-auth remote message decompression. The advisory included a CVSS 8.6 score, noted the affected code path, and pointed to upstream patches in pull request #4128.
ClusterLabs published pull request #4128 with fixes for integer overflows, size validation issues, and unbounded memory allocation in Pacemaker's remote message handling code. The changes added safer arithmetic and validation checks and imposed a 20 MB maximum remote message size.
A Red Hat Bugzilla report described CVE-2026-10649, a high-severity integer overflow in Pacemaker's remote message decompression that could let an unauthenticated network attacker cause memory corruption and denial of service via the CIB remote listener. The report said no released fix was established at that time and upstream had not yet been notified.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcegithub.com
Open sourceopenwall.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.