In the Linux kernel, the following vulnerability has been resolved:
ocfs2: validate lengths in dlm_mig_lockres_handler
A node receiving a DLM_MIG_LOCKRES message trusts several fields of the
peer-supplied dlm_migratable_lockres without validation. num_locks and
lockname_len are bounded only on the sending side, and the message is
never checked to actually carry num_locks migratable_lock entries. As a
result dlm_process_recovery_data() walks mres->ml[0..num_locks) past the
kmalloc(data_len) copy of the message (an out-of-bounds read that ends in
a BUG_ON panic), and dlm_init_lockres() copies lockname_len bytes into the
fixed 32-byte o2dlm_lockname slab object (a heap out-of-bounds write).
Both are reachable by any node in the domain.
Validate these fields right after dlm_grab(), before anything uses them --
including the not-joined error path, which already prints mres->lockname
with the unbounded lockname_len as a %.*s precision. Reject the message
unless lockname_len <= DLM_LOCKID_NAME_MAX, num_locks <=
DLM_MAX_MIGRATABLE_LOCKS (the bound the sender already asserts), and the
payload is large enough to hold the claimed locks. Conforming recovery
and migration messages are unaffected.
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8
AV:N - DLM_MIG_LOCKRES is received and dispatched by the ocfs2 o2net TCP cluster transport, so dlm_mig_lockres_handler() is reached through network protocol messages from a peer node.
AC:L - A cluster peer can send a crafted DLM_MIG_LOCKRES with attacker-chosen lockname_len and num_locks; the heap overflow and BUG_ON are deterministic and require no race or other condition outside the attacker's control.
PR:N - o2net gates peers by configured node IP, heartbeat, and the DLM domain key, with no user authentication or target-local privilege check before the handler runs, so exploitation needs no account on the victim.
UI:N - Once the OCFS2/DLM domain is joined, exploitation is driven entirely by attacker-sent o2net messages and requires no victim user action such as mounting or opening a file.
S:U - The heap corruption and resulting kernel impact remain within the same kernel and OCFS2 cluster-node security authority and do not cross a guest-to-host or IOMMU boundary.
C:H - Unchecked lockname_len and num_locks produce a heap out-of-bounds write of attacker-controlled bytes and an out-of-bounds read past the kmalloc message copy, which can disclose adjacent kernel memory.
I:H - dlm_init_lockres() memcpy()s up to 255 attacker-controlled bytes into a 32-byte o2dlm_lockname slab object, a heap out-of-bounds write that can overwrite adjacent objects and hijack kernel control flow.
A:H - dlm_process_recovery_data() walks mres->ml[] past the allocated message and hits BUG_ON, and the heap overflow can oops or panic the receiving node.
| Attack Vector |
Network |
Scope |
Unchanged |
| Attack Complexity |
Low |
Confidentiality Impact |
High |
| Privileges Required |
None |
Integrity Impact |
High |
| User Interaction |
None |
Availability Impact |
High |
AV:N - DLM_MIG_LOCKRES is received and dispatched by the ocfs2 o2net TCP cluster transport, so dlm_mig_lockres_handler() is reached through network protocol messages from a peer node.
AC:L - A cluster peer can send a crafted DLM_MIG_LOCKRES with attacker-chosen lockname_len and num_locks; the heap overflow and BUG_ON are deterministic and require no race or other condition outside the attacker's control.
PR:N - o2net gates peers by configured node IP, heartbeat, and the DLM domain key, with no user authentication or target-local privilege check before the handler runs, so exploitation needs no account on the victim.
UI:N - Once the OCFS2/DLM domain is joined, exploitation is driven entirely by attacker-sent o2net messages and requires no victim user action such as mounting or opening a file.
S:U - The heap corruption and resulting kernel impact remain within the same kernel and OCFS2 cluster-node security authority and do not cross a guest-to-host or IOMMU boundary.
C:H - Unchecked lockname_len and num_locks produce a heap out-of-bounds write of attacker-controlled bytes and an out-of-bounds read past the kmalloc message copy, which can disclose adjacent kernel memory.
I:H - dlm_init_lockres() memcpy()s up to 255 attacker-controlled bytes into a 32-byte o2dlm_lockname slab object, a heap out-of-bounds write that can overwrite adjacent objects and hijack kernel control flow.
A:H - dlm_process_recovery_data() walks mres->ml[] past the allocated message and hits BUG_ON, and the heap overflow can oops or panic the receiving node.
CVSS 3.1