CVE-2026-89494

Source
https://cve.org/CVERecord?id=CVE-2026-89494
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89494.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-89494
Downstream
Published
2026-09-11T19:43:45Z
Modified
2026-09-15T03:48:19Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ocfs2: validate lengths in dlm_mig_lockres_handler
Details

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: validate lengths in dlm_mig_lockres_handler

A node receiving a DLM_MIG_LOCKRES message trusts several fields of the peer-supplied dlm_migratable_lockres without validation. num_locks and lockname_len are bounded only on the sending side, and the message is never checked to actually carry num_locks migratable_lock entries. As a result dlm_process_recovery_data() walks mres->ml[0..num_locks) past the kmalloc(data_len) copy of the message (an out-of-bounds read that ends in a BUG_ON panic), and dlm_init_lockres() copies lockname_len bytes into the fixed 32-byte o2dlm_lockname slab object (a heap out-of-bounds write). Both are reachable by any node in the domain.

Validate these fields right after dlm_grab(), before anything uses them -- including the not-joined error path, which already prints mres->lockname with the unbounded lockname_len as a %.*s precision. Reject the message unless lockname_len <= DLM_LOCKID_NAME_MAX, num_locks <= DLM_MAX_MIGRATABLE_LOCKS (the bound the sender already asserts), and the payload is large enough to hold the claimed locks. Conforming recovery and migration messages are unaffected.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89494.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6714d8e86bf443f6f7af50f9d432025649f091f5
Fixed
4a5798253212093b9ff7d90c6cfbe348bcda1594
Fixed
dce05b17db862f47ff60614017abe639b2e71cad
Fixed
0e999d56917f861f97adb961617b1828c9eb4733
Fixed
77686fa5bba135252d348e2dacf481fc19f60c41
Fixed
f33041906885f96e190cde54e61ddc69de39e3ee
Fixed
50c4cc9183e11f83427efbf770f54851f4471c02
Fixed
a8facb1670b4a0612183198e758d9539ef628ed9
Fixed
b54e03d9b3697d25f4a0063cf717d459c5e3ad94

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89494.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.16
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.109
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.50
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-89494.json"