CVE-2026-89494
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: validate lengths in dlmmiglockres_handler
A node receiving a DLMMIGLOCKRES message trusts several fields of the
peer-supplied dlmmigratablelockres without validation. num_locks and
lockname_len are bounded only on the sending side, and the message is
never checked to actually carry numlocks migratablelock entries. As a
result dlmprocessrecoverydata() walks mres->ml[0..numlocks) past the
kmalloc(data_len) copy of the message (an out-of-bounds read that ends in
a BUGON panic), and dlminitlockres() copies locknamelen bytes into the
fixed 32-byte o2dlm_lockname slab object (a heap out-of-bounds write).
Both are reachable by any node in the domain.
Validate these fields right after dlm_grab(), before anything uses them --
including the not-joined error path, which already prints mres->lockname
with the unbounded lockname_len as a %.*s precision. Reject the message
unless locknamelen <= DLMLOCKIDNAMEMAX, num_locks <=
DLMMAXMIGRATABLE_LOCKS (the bound the sender already asserts), and the
payload is large enough to hold the claimed locks. Conforming recovery
and migration messages are unaffected.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/0e999d56917f861f97adb961617b1828c9eb4733, https://git.kernel.org/stable/c/4a5798253212093b9ff7d90c6cfbe348bcda1594, https://git.kernel.org/stable/c/50c4cc9183e11f83427efbf770f54851f4471c02, https://git.kernel.org/stable/c/77686fa5bba135252d348e2dacf481fc19f60c41, https://git.kernel.org/stable/c/a8facb1670b4a0612183198e758d9539ef628ed9, https://git.kernel.org/stable/c/b54e03d9b3697d25f4a0063cf717d459c5e3ad94, https://git.kernel.org/stable/c/dce05b17db862f47ff60614017abe639b2e71cad, https://git.kernel.org/stable/c/f33041906885f96e190cde54e61ddc69de39e3ee, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/89xxx/CVE-2026-89494.json, https://nvd.nist.gov/vuln/detail/CVE-2026-89494, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git