CRITICAL Introduced in 2.6.16
ocfs2 MigLockres OOB
CVE-2026-89494
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
KernelScan AI8.0HIGH
01Description
In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler A node receiving a DLM_MIG_LOCKRES message trusts several fields of the peer-supplied dlm_migratable_lockres without validation. num_locks and lockname_len are bounded only on the sending side, and the message is never checked to actually carry num_locks migratable_lock entries. As a result dlm_process_recovery_data() walks mres->ml[0..num_locks) past the kmalloc(data_len) copy of the message (an out-of-bounds read that ends in a BUG_ON panic), and dlm_init_lockres() copies lockname_len bytes into the fixed 32-byte o2dlm_lockname slab object (a heap out-of-bounds write). Both are reachable by any node in the domain. Validate these fields right after dlm_grab(), before anything uses them -- including the not-joined error path, which already prints mres->lockname with the unbounded lockname_len as a %.*s precision. Reject the message unless lockname_len <= DLM_LOCKID_NAME_MAX, num_locks <= DLM_MAX_MIGRATABLE_LOCKS (the bound the sender already asserts), and the payload is large enough to hold the claimed locks. Conforming recovery and migration messages are unaffected.
02KernelScan AI Analysis
Risk summary
Any node in an OCFS2 cluster domain can send a malformed DLM lock-resource migration message to a peer, causing an out-of-bounds heap write or an out-of-bounds read that panics the kernel. The vulnerability requires the target to be part of an OCFS2 cluster and the attacker to have access to the cluster interconnect or control of a peer node. Products not using OCFS2 clustering are unaffected.
Vulnerability analysis
The OCFS2 distributed lock manager processes lock-resource migration messages from peer cluster nodes without validating the claimed number of locks or the lockname length in the message payload. A malicious node in the cluster domain can send a migration message with an inflated lock count, causing the receiving kernel to walk past the end of the message buffer and hit a kernel panic, or with an oversized lockname, causing a heap buffer overflow when the name is copied into a fixed-size lock-resource object. The fix adds bounds checks on the lockname length, lock count, and total payload size immediately after the message is received and before any field is used, rejecting malformed messages early so that conforming migration and recovery traffic is unaffected. The vulnerability is reachable by any node that has joined the OCFS2 cluster domain, which requires root on a cluster node and network access to the cluster interconnect.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.1 | 2.6.16 | 6.1.188 | 0e999d56917f |
| 6.18 | 2.6.16 | 6.18.50 | 50c4cc9183e1 |
| 6.6 | 2.6.16 | 6.6.157 | 77686fa5bba1 |
| mainline | 2.6.16 | 7.3-rc1 | b54e03d9b369 |
| 5.10 | 2.6.16 | 5.10.270 | 4a5798253212 |
| 7.2 | 2.6.16 | 7.2.4 | a8facb1670b4 |
| 5.15 | 2.6.16 | 5.15.221 | dce05b17db86 |
| 6.12 | 2.6.16 | 6.12.109 | f33041906885 |