In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handler Patch series "ocfs2/dlm:… (CVE-2026-89495)
A heap out-of-bounds write vulnerability in the Linux kernel's ocfs2 distributed lock manager (DLM) was resolved. The vulnerability arises because the DLM migration and recovery message handlers trust peer-supplied length fields without proper bounds checking, allowing a malicious cluster node to send malformed messages that cause memory corruption or kernel panic. The issue affects the dlm_migrate_request_handler and dlm_mig_lockres_handler functions, which copy attacker-controlled data into fixed-size buffers without validation. The vulnerability requires the attacker to be a member of the DLM cluster domain. Patches have been released that add proper bounds checking to these handlers, preventing malformed messages from causing out-of-bounds writes or kernel panics.
AI Analysis
Technical Summary
The Linux kernel ocfs2 distributed lock manager (DLM) had a vulnerability (CVE-2026-89495) where peer-supplied length fields in migration and recovery messages were not properly bounded. Specifically, dlm_migrate_request_handler passed an unchecked name length to dlm_init_mle(), causing a heap out-of-bounds write of up to ~215 bytes. Similarly, dlm_mig_lockres_handler passed an unchecked lockname length to dlm_init_lockres(), causing another heap out-of-bounds write of up to ~223 bytes. Additionally, the handler trusted the number of locks without verifying message size, leading to an out-of-bounds read and kernel panic. These flaws allow any node in the DLM domain, including malicious or compromised members, to corrupt or crash other cluster nodes. The patches add bounds checking to reject oversized names and validate message sizes. Conforming cluster traffic is unaffected.
Potential Impact
A malicious or compromised node within the ocfs2 DLM cluster domain can send specially crafted migration or recovery messages that cause heap out-of-bounds writes or out-of-bounds reads in other cluster nodes. This can lead to memory corruption or kernel panic, potentially disrupting cluster operations. There is no local trigger; the attacker must already be a member of the cluster domain. Conforming cluster traffic is not affected.
Mitigation Recommendations
Patches have been released that add proper bounds checking to the affected DLM message handlers, preventing out-of-bounds memory operations. Cluster operators should apply these kernel patches to ensure the vulnerability is mitigated. Since the vulnerability requires cluster membership, restricting cluster membership to trusted nodes also reduces risk. There is no indication that additional mitigations are necessary beyond applying the official fixes.
In the Linux kernel, the following vulnerability has been resolved: ocfs2: bound namelen in dlm_migrate_request_handler Patch series "ocfs2/dlm:… (CVE-2026-89495)
Description
A heap out-of-bounds write vulnerability in the Linux kernel's ocfs2 distributed lock manager (DLM) was resolved. The vulnerability arises because the DLM migration and recovery message handlers trust peer-supplied length fields without proper bounds checking, allowing a malicious cluster node to send malformed messages that cause memory corruption or kernel panic. The issue affects the dlm_migrate_request_handler and dlm_mig_lockres_handler functions, which copy attacker-controlled data into fixed-size buffers without validation. The vulnerability requires the attacker to be a member of the DLM cluster domain. Patches have been released that add proper bounds checking to these handlers, preventing malformed messages from causing out-of-bounds writes or kernel panics.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel ocfs2 distributed lock manager (DLM) had a vulnerability (CVE-2026-89495) where peer-supplied length fields in migration and recovery messages were not properly bounded. Specifically, dlm_migrate_request_handler passed an unchecked name length to dlm_init_mle(), causing a heap out-of-bounds write of up to ~215 bytes. Similarly, dlm_mig_lockres_handler passed an unchecked lockname length to dlm_init_lockres(), causing another heap out-of-bounds write of up to ~223 bytes. Additionally, the handler trusted the number of locks without verifying message size, leading to an out-of-bounds read and kernel panic. These flaws allow any node in the DLM domain, including malicious or compromised members, to corrupt or crash other cluster nodes. The patches add bounds checking to reject oversized names and validate message sizes. Conforming cluster traffic is unaffected.
Potential Impact
A malicious or compromised node within the ocfs2 DLM cluster domain can send specially crafted migration or recovery messages that cause heap out-of-bounds writes or out-of-bounds reads in other cluster nodes. This can lead to memory corruption or kernel panic, potentially disrupting cluster operations. There is no local trigger; the attacker must already be a member of the cluster domain. Conforming cluster traffic is not affected.
Mitigation Recommendations
Patches have been released that add proper bounds checking to the affected DLM message handlers, preventing out-of-bounds memory operations. Cluster operators should apply these kernel patches to ensure the vulnerability is mitigated. Since the vulnerability requires cluster membership, restricting cluster membership to trusted nodes also reduces risk. There is no indication that additional mitigations are necessary beyond applying the official fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3pmg-pq3r-v8mc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-89495"]
Threat ID: 6aa4a01755bf5e2cf5a866fa
Added to database: 09/12/2026, 00:43:03 UTC
Last enriched: 09/12/2026, 01:13:09 UTC
Last updated: 09/12/2026, 01:13:09 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.