DSA-6261-1

NameDSA-6261-1
Descriptioncorosync - security update
SourceDebian
ReferencesCVE-2026-35091, CVE-2026-35092

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
corosync (PTS)bookworm3.1.7-1+deb12u1vulnerable
bookworm (security)3.1.7-1+deb12u2fixed
trixie3.1.9-2vulnerable
trixie (security)3.1.9-2+deb13u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
corosyncsourcebookworm3.1.7-1+deb12u2
corosyncsourcetrixie3.1.9-2+deb13u1

Search for package or bug name: Reporting problems