CVE-2026-53043
published 2026-06-24CVE-2026-53043: In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regions() Patch series "ocfs2/dlm: fix two…
PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.52%
40.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
ocfs2/dlm: validate qr_numregions in dlm_match_regions()
Patch series "ocfs2/dlm: fix two bugs in dlm_match_regions()".
In dlm_match_regions(), the qr_numregions field from a DLM_QUERY_REGION
network message is used to drive loops over the qr_regions buffer without
sufficient validation. This series fixes two issues:
- Patch 1 adds a bounds check to reject messages where qr_numregions
exceeds O2NM_MAX_REGIONS. The o2net layer only validates message
byte length; it does not constrain field values, so a crafted message
can set qr_numregions up to 255 and trigger out-of-bounds reads past
the 1024-byte qr_regions buffer.
- Patch 2 fixes an off-by-one in the local-vs-remote comparison loop,
which uses ' 32 causes
out-of-bounds reads past the qr_regions buffer.
Add a bounds check for qr_numregions before entering the loops.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= ea2034416b54700e30371f2ad6517cbb94674083 < d3d5efade0c79dac1cac98c0cb1115432f804439 | d3d5efade0c79dac1cac98c0cb1115432f804439 |
| linux | linux | >= ea2034416b54700e30371f2ad6517cbb94674083 < f69551139caf6d24242a0ad049ee46b264e3aee0 | f69551139caf6d24242a0ad049ee46b264e3aee0 |
| linux | linux | >= ea2034416b54700e30371f2ad6517cbb94674083 < 1f8b91275912cd428289c1fb424bebd7ff5302bd | 1f8b91275912cd428289c1fb424bebd7ff5302bd |
| linux | linux | >= ea2034416b54700e30371f2ad6517cbb94674083 < f37de46149db49abd2b24f4f0c5a88cf4dfb5f47 | f37de46149db49abd2b24f4f0c5a88cf4dfb5f47 |
| linux | linux | >= ea2034416b54700e30371f2ad6517cbb94674083 < 6c6e8fc3c007319981647b410c29bb5775048551 | 6c6e8fc3c007319981647b410c29bb5775048551 |
| linux | linux | >= ea2034416b54700e30371f2ad6517cbb94674083 < 3f474c33ebc2e2ca3fcb587d7de4375348f13373 | 3f474c33ebc2e2ca3fcb587d7de4375348f13373 |
| linux | linux | >= ea2034416b54700e30371f2ad6517cbb94674083 < 3c2d0de23ae4be22b6c18e8f0915be74d3b5fb21 | 3c2d0de23ae4be22b6c18e8f0915be74d3b5fb21 |
| linux | linux | >= ea2034416b54700e30371f2ad6517cbb94674083 < 7ab3fbb01bc6d79091bc375e5235d360cd9b78be | 7ab3fbb01bc6d79091bc375e5235d360cd9b78be |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ocfs2/dlm: validate qr_numregions in dlm_match_regions()
vendor_redhat·2026-06-24
CVE-2026-53043 CWE-1285 kernel: ocfs2/dlm: validate qr_numregions in dlm_match_regions()
kernel: ocfs2/dlm: validate qr_numregions in dlm_match_regions()
A flaw was found in the Linux kernel's Oracle Cluster File System 2 (OCFS2) Distributed Lock Manager (DLM). A remote attacker could exploit this vulnerability by sending a specially crafted network message. Insufficient validation of the qr_numregions field in the dlm_match_regions() function allows for out-of-bounds reads past a buffer, which could lead to information disclosure or a denial of service.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-r
VulDB
Linux Kernel up to 7.0.9 ocfs2 dlm_match_regions qr_numregions off-by-one
vuldb·2026-06-24
CVE-2026-53043 [CRITICAL] Linux Kernel up to 7.0.9 ocfs2 dlm_match_regions qr_numregions off-by-one
A vulnerability marked as critical has been reported in Linux Kernel up to 7.0.9. This vulnerability affects the function dlm_match_regions of the component ocfs2. The manipulation of the argument qr_numregions leads to off-by-one.
This vulnerability is referenced as CVE-2026-53043. The attack needs to be initiated within the local network. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regions() Patch series "ocfs2/dlm: fix two bugs in dlm_match_regions()".
ghsa_unreviewed·2026-06-24
CVE-2026-53043 In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regions() Patch series "ocfs2/dlm: fix two bugs in dlm_match_regions()".
In the Linux kernel, the following vulnerability has been resolved:
ocfs2/dlm: validate qr_numregions in dlm_match_regions()
Patch series "ocfs2/dlm: fix two bugs in dlm_match_regions()".
In dlm_match_regions(), the qr_numregions field from a DLM_QUERY_REGION
network message is used to drive loops over the qr_regions buffer without
sufficient validation. This series fixes two issues:
- Patch 1 adds a bounds check to reject messages where qr_numregions
exceeds O2NM_MAX_REGIONS. The o2net layer only validates message
byte length; it does not constrain field values, so a crafted message
can set qr_numregions up to 255 and trigger out-of-bounds reads past
the 1024-byte qr_regions buffer.
- Patch 2 fixes an off-by-one in the local-vs-remote comparison loop,
which uses ' 32 causes
out-of-bo
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/1f8b91275912cd428289c1fb424bebd7ff5302bdhttps://git.kernel.org/stable/c/3c2d0de23ae4be22b6c18e8f0915be74d3b5fb21https://git.kernel.org/stable/c/3f474c33ebc2e2ca3fcb587d7de4375348f13373https://git.kernel.org/stable/c/6c6e8fc3c007319981647b410c29bb5775048551https://git.kernel.org/stable/c/7ab3fbb01bc6d79091bc375e5235d360cd9b78behttps://git.kernel.org/stable/c/d3d5efade0c79dac1cac98c0cb1115432f804439https://git.kernel.org/stable/c/f37de46149db49abd2b24f4f0c5a88cf4dfb5f47https://git.kernel.org/stable/c/f69551139caf6d24242a0ad049ee46b264e3aee0
2026-06-24
Published