9.8

CVE-2026-74401

dlm: fix add msg handle in send_queue ordered

In the Linux kernel, the following vulnerability has been resolved:

dlm: fix add msg handle in send_queue ordered

In a benchmark scenario triggering a lot of requests that triggers a lot
of DLM messages on the network it can be that the mh->seq is not ordered
according the oldest seq number. This ordering is required by
dlm_receive_ack as "before(mh->seq, seq)" will stop to check for older
sequence numbers that are ordered in the tail of "node->send_queue".

The side effects of not having it correct ordered regarding
"before(mh->seq, seq)" are refcounting issues and use-after free.

I only was able to reproduce this issue in a experimental DLM branch
and a user space DLM benchmark that uses io_uring. After changing this I
don't experienced any refcounting with the sending buffer issues anymore.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 489d8e559c6596eb08e16447d9830bc39afbe54e
Version < ae9e534e502a0f48c12baf83608c5de0ff0eab11
Status affected
Version 489d8e559c6596eb08e16447d9830bc39afbe54e
Version < 6369619f1b665f12d8c99cc6ff733c64eb08b22e
Status affected
Version 489d8e559c6596eb08e16447d9830bc39afbe54e
Version < 712714f818d83373847874ab0f8e426be79296cf
Status affected
Version 489d8e559c6596eb08e16447d9830bc39afbe54e
Version < 4d45250b1d22960f86d83245be188b16e456218b
Status affected
Version 489d8e559c6596eb08e16447d9830bc39afbe54e
Version < d2248cb70c070f8f04762872772e155b59016f17
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.14
Status affected
Version 0
Version < 5.14
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.374
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ae9e534e502a0f48c12baf83608c5de0ff0eab11
https://git.kernel.org/stable/c/6369619f1b665f12d8c99cc6ff733c64eb08b22e
https://git.kernel.org/stable/c/712714f818d83373847874ab0f8e426be79296cf
https://git.kernel.org/stable/c/4d45250b1d22960f86d83245be188b16e456218b
https://git.kernel.org/stable/c/d2248cb70c070f8f04762872772e155b59016f17