9.8

CVE-2026-89494

ocfs2: validate lengths in dlm_mig_lockres_handler

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate lengths in dlm_mig_lockres_handler

A node receiving a DLM_MIG_LOCKRES message trusts several fields of the
peer-supplied dlm_migratable_lockres without validation.  num_locks and
lockname_len are bounded only on the sending side, and the message is
never checked to actually carry num_locks migratable_lock entries.  As a
result dlm_process_recovery_data() walks mres->ml[0..num_locks) past the
kmalloc(data_len) copy of the message (an out-of-bounds read that ends in
a BUG_ON panic), and dlm_init_lockres() copies lockname_len bytes into the
fixed 32-byte o2dlm_lockname slab object (a heap out-of-bounds write). 
Both are reachable by any node in the domain.

Validate these fields right after dlm_grab(), before anything uses them --
including the not-joined error path, which already prints mres->lockname
with the unbounded lockname_len as a %.*s precision.  Reject the message
unless lockname_len <= DLM_LOCKID_NAME_MAX, num_locks <=
DLM_MAX_MIGRATABLE_LOCKS (the bound the sender already asserts), and the
payload is large enough to hold the claimed locks.  Conforming recovery
and migration messages are unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 6714d8e86bf443f6f7af50f9d432025649f091f5
Version < 4a5798253212093b9ff7d90c6cfbe348bcda1594
Status affected
Version 6714d8e86bf443f6f7af50f9d432025649f091f5
Version < dce05b17db862f47ff60614017abe639b2e71cad
Status affected
Version 6714d8e86bf443f6f7af50f9d432025649f091f5
Version < 0e999d56917f861f97adb961617b1828c9eb4733
Status affected
Version 6714d8e86bf443f6f7af50f9d432025649f091f5
Version < 77686fa5bba135252d348e2dacf481fc19f60c41
Status affected
Version 6714d8e86bf443f6f7af50f9d432025649f091f5
Version < f33041906885f96e190cde54e61ddc69de39e3ee
Status affected
Version 6714d8e86bf443f6f7af50f9d432025649f091f5
Version < 50c4cc9183e11f83427efbf770f54851f4471c02
Status affected
Version 6714d8e86bf443f6f7af50f9d432025649f091f5
Version < a8facb1670b4a0612183198e758d9539ef628ed9
Status affected
Version 6714d8e86bf443f6f7af50f9d432025649f091f5
Version < b54e03d9b3697d25f4a0063cf717d459c5e3ad94
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.16
Status affected
Version 0
Version < 2.6.16
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.481
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f33041906885f96e190cde54e61ddc69de39e3ee
https://git.kernel.org/stable/c/50c4cc9183e11f83427efbf770f54851f4471c02
https://git.kernel.org/stable/c/a8facb1670b4a0612183198e758d9539ef628ed9
https://git.kernel.org/stable/c/b54e03d9b3697d25f4a0063cf717d459c5e3ad94
https://git.kernel.org/stable/c/0e999d56917f861f97adb961617b1828c9eb4733
https://git.kernel.org/stable/c/4a5798253212093b9ff7d90c6cfbe348bcda1594
https://git.kernel.org/stable/c/77686fa5bba135252d348e2dacf481fc19f60c41
https://git.kernel.org/stable/c/dce05b17db862f47ff60614017abe639b2e71cad