A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
https://github.com/clusterLabs/pacemaker/pull/4128
https://bugzilla.redhat.com/show_bug.cgi?id=2462817