CVE-2026-89494 PUBLISHED

ocfs2: validate lengths in dlm_mig_lockres_handler

Assigner: Linux
Reserved: 11.09.2026 Published: 11.09.2026 Updated: 13.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate lengths in dlm_mig_lockres_handler

A node receiving a DLM_MIG_LOCKRES message trusts several fields of the peer-supplied dlm_migratable_lockres without validation. num_locks and lockname_len are bounded only on the sending side, and the message is never checked to actually carry num_locks migratable_lock entries. As a result dlm_process_recovery_data() walks mres->ml[0..num_locks) past the kmalloc(data_len) copy of the message (an out-of-bounds read that ends in a BUG_ON panic), and dlm_init_lockres() copies lockname_len bytes into the fixed 32-byte o2dlm_lockname slab object (a heap out-of-bounds write). Both are reachable by any node in the domain.

Validate these fields right after dlm_grab(), before anything uses them -- including the not-joined error path, which already prints mres->lockname with the unbounded lockname_len as a %.*s precision. Reject the message unless lockname_len <= DLM_LOCKID_NAME_MAX, num_locks <= DLM_MAX_MIGRATABLE_LOCKS (the bound the sender already asserts), and the payload is large enough to hold the claimed locks. Conforming recovery and migration messages are unaffected.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

AV:N - DLM_MIG_LOCKRES is received and dispatched by the ocfs2 o2net TCP cluster transport, so dlm_mig_lockres_handler() is reached through network protocol messages from a peer node. AC:L - A cluster peer can send a crafted DLM_MIG_LOCKRES with attacker-chosen lockname_len and num_locks; the heap overflow and BUG_ON are deterministic and require no race or other condition outside the attacker's control. PR:N - o2net gates peers by configured node IP, heartbeat, and the DLM domain key, with no user authentication or target-local privilege check before the handler runs, so exploitation needs no account on the victim. UI:N - Once the OCFS2/DLM domain is joined, exploitation is driven entirely by attacker-sent o2net messages and requires no victim user action such as mounting or opening a file. S:U - The heap corruption and resulting kernel impact remain within the same kernel and OCFS2 cluster-node security authority and do not cross a guest-to-host or IOMMU boundary. C:H - Unchecked lockname_len and num_locks produce a heap out-of-bounds write of attacker-controlled bytes and an out-of-bounds read past the kmalloc message copy, which can disclose adjacent kernel memory. I:H - dlm_init_lockres() memcpy()s up to 255 attacker-controlled bytes into a 32-byte o2dlm_lockname slab object, a heap out-of-bounds write that can overwrite adjacent objects and hijack kernel control flow. A:H - dlm_process_recovery_data() walks mres->ml[] past the allocated message and hits BUG_ON, and the heap overflow can oops or panic the receiving node.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 6714d8e86bf443f6f7af50f9d432025649f091f5 to f33041906885f96e190cde54e61ddc69de39e3ee (excl.)
  • affected from 6714d8e86bf443f6f7af50f9d432025649f091f5 to 50c4cc9183e11f83427efbf770f54851f4471c02 (excl.)
  • affected from 6714d8e86bf443f6f7af50f9d432025649f091f5 to a8facb1670b4a0612183198e758d9539ef628ed9 (excl.)
  • affected from 6714d8e86bf443f6f7af50f9d432025649f091f5 to b54e03d9b3697d25f4a0063cf717d459c5e3ad94 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.16 is affected
  • unaffected from 0 to 2.6.16 (excl.)
  • unaffected from 6.12.109 to 6.12.* (incl.)
  • unaffected from 6.18.50 to 6.18.* (incl.)
  • unaffected from 7.2.4 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References