๐Ÿ” CVE Alert

CVE-2026-89494

CRITICAL 9.8

ocfs2: validate lengths in dlm_mig_lockres_handler

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler A node receiving a DLM_MIG_LOCKRES message trusts several fields of the peer-supplied dlm_migratable_lockres without validation. num_locks and lockname_len are bounded only on the sending side, and the message is never checked to actually carry num_locks migratable_lock entries. As a result dlm_process_recovery_data() walks mres->ml[0..num_locks) past the kmalloc(data_len) copy of the message (an out-of-bounds read that ends in a BUG_ON panic), and dlm_init_lockres() copies lockname_len bytes into the fixed 32-byte o2dlm_lockname slab object (a heap out-of-bounds write). Both are reachable by any node in the domain. Validate these fields right after dlm_grab(), before anything uses them -- including the not-joined error path, which already prints mres->lockname with the unbounded lockname_len as a %.*s precision. Reject the message unless lockname_len <= DLM_LOCKID_NAME_MAX, num_locks <= DLM_MAX_MIGRATABLE_LOCKS (the bound the sender already asserts), and the payload is large enough to hold the claimed locks. Conforming recovery and migration messages are unaffected.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new critical vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
6714d8e86bf443f6f7af50f9d432025649f091f5 < 4a5798253212093b9ff7d90c6cfbe348bcda1594 6714d8e86bf443f6f7af50f9d432025649f091f5 < dce05b17db862f47ff60614017abe639b2e71cad 6714d8e86bf443f6f7af50f9d432025649f091f5 < 0e999d56917f861f97adb961617b1828c9eb4733 6714d8e86bf443f6f7af50f9d432025649f091f5 < 77686fa5bba135252d348e2dacf481fc19f60c41 6714d8e86bf443f6f7af50f9d432025649f091f5 < f33041906885f96e190cde54e61ddc69de39e3ee 6714d8e86bf443f6f7af50f9d432025649f091f5 < 50c4cc9183e11f83427efbf770f54851f4471c02 6714d8e86bf443f6f7af50f9d432025649f091f5 < a8facb1670b4a0612183198e758d9539ef628ed9 6714d8e86bf443f6f7af50f9d432025649f091f5 < b54e03d9b3697d25f4a0063cf717d459c5e3ad94
Linux / Linux
2.6.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/4a5798253212093b9ff7d90c6cfbe348bcda1594 git.kernel.org: https://git.kernel.org/stable/c/dce05b17db862f47ff60614017abe639b2e71cad git.kernel.org: https://git.kernel.org/stable/c/0e999d56917f861f97adb961617b1828c9eb4733 git.kernel.org: https://git.kernel.org/stable/c/77686fa5bba135252d348e2dacf481fc19f60c41 git.kernel.org: https://git.kernel.org/stable/c/f33041906885f96e190cde54e61ddc69de39e3ee git.kernel.org: https://git.kernel.org/stable/c/50c4cc9183e11f83427efbf770f54851f4471c02 git.kernel.org: https://git.kernel.org/stable/c/a8facb1670b4a0612183198e758d9539ef628ed9 git.kernel.org: https://git.kernel.org/stable/c/b54e03d9b3697d25f4a0063cf717d459c5e3ad94