CVE-2026-89494
Last modified
CVE-2026-89494 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler A node receiving a DLM_MIG_LOCKRES message trusts several fields of the peer-supplied dlm_migratable_lockres without validation. num_locks and lockname_len are bounded only on the sending side, and the message is never checked to actually carry num_locks migratable_lock entries. EPSS estimates a 0.63% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ocfs2: validate lengths in dlm_mig_lockres_handler A node receiving a DLM_MIG_LOCKRES message trusts several fields of the peer-supplied dlm_migratable_lockres without validation. num_locks and lockname_len are bounded only on the sending side, and the message is never checked to actually carry num_locks migratable_lock entries. As a result dlm_process_recovery_data() walks mres->ml[0..num_locks) past the kmalloc(data_len) copy of the message (an out-of-bounds read that ends in a BUG_ON panic), and dlm_init_lockres() copies lockname_len bytes into the fixed 32-byte o2dlm_lockname slab object (a heap out-of-bounds write). Both are reachable by any node in the domain. Validate these fields right after dlm_grab(), before anything uses them -- including the not-joined error path, which already prints mres->lockname with the unbounded lockname_len as a %.*s precision. Reject the message unless lockname_len <= DLM_LOCKID_NAME_MAX, num_locks <= DLM_MAX_MIGRATABLE_LOCKS (the bound the sender already asserts), and the payload is large enough to hold the claimed locks. Conforming recovery and migration messages are unaffected.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 6714d8e86bf443f6f7af50f9d432025649f091f5, < 4a5798253212093b9ff7d90c6cfbe348bcda1594; >= 6714d8e86bf443f6f7af50f9d432025649f091f5, < dce05b17db862f47ff60614017abe639b2e71cad; >= 6714d8e86bf443f6f7af50f9d432025649f091f5, < 0e999d56917f861f97adb961617b1828c9eb4733; >= 6714d8e86bf443f6f7af50f9d432025649f091f5, < 77686fa5bba135252d348e2dacf481fc19f60c41; >= 6714d8e86bf443f6f7af50f9d432025649f091f5, < f33041906885f96e190cde54e61ddc69de39e3ee; >= 6714d8e86bf443f6f7af50f9d432025649f091f5, < 50c4cc9183e11f83427efbf770f54851f4471c02; >= 6714d8e86bf443f6f7af50f9d432025649f091f5, < a8facb1670b4a0612183198e758d9539ef628ed9; >= 6714d8e86bf443f6f7af50f9d432025649f091f5, < b54e03d9b3697d25f4a0063cf717d459c5e3ad94 |
| Linux | Linux | 2.6.16 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-89494?
How severe is CVE-2026-89494?
How do I fix CVE-2026-89494?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-89489In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-8949Integer overflow in the Widget: Win32 component. This vulner…7.5
- CVE-2026-89490In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89491In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89492In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-89493In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-89495In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-89496In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89497In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-89498In the Linux kernel, the following vulnerability has been re…
- CVE-2026-89499In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-8950Same-origin policy bypass in the Networking: HTTP component.…9.3
Are you affected by CVE-2026-89494?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
