cbcvebase.
CVE-2026-53043
published 2026-06-24

CVE-2026-53043: In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regions() Patch series "ocfs2/dlm: fix two…

PriorityP353critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
0.52%
40.6th percentile
In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regions() Patch series "ocfs2/dlm: fix two bugs in dlm_match_regions()". In dlm_match_regions(), the qr_numregions field from a DLM_QUERY_REGION network message is used to drive loops over the qr_regions buffer without sufficient validation. This series fixes two issues: - Patch 1 adds a bounds check to reject messages where qr_numregions exceeds O2NM_MAX_REGIONS. The o2net layer only validates message byte length; it does not constrain field values, so a crafted message can set qr_numregions up to 255 and trigger out-of-bounds reads past the 1024-byte qr_regions buffer. - Patch 2 fixes an off-by-one in the local-vs-remote comparison loop, which uses ' 32 causes out-of-bounds reads past the qr_regions buffer. Add a bounds check for qr_numregions before entering the loops.

Affected

9 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= ea2034416b54700e30371f2ad6517cbb94674083 < d3d5efade0c79dac1cac98c0cb1115432f804439d3d5efade0c79dac1cac98c0cb1115432f804439
linuxlinux>= ea2034416b54700e30371f2ad6517cbb94674083 < f69551139caf6d24242a0ad049ee46b264e3aee0f69551139caf6d24242a0ad049ee46b264e3aee0
linuxlinux>= ea2034416b54700e30371f2ad6517cbb94674083 < 1f8b91275912cd428289c1fb424bebd7ff5302bd1f8b91275912cd428289c1fb424bebd7ff5302bd
linuxlinux>= ea2034416b54700e30371f2ad6517cbb94674083 < f37de46149db49abd2b24f4f0c5a88cf4dfb5f47f37de46149db49abd2b24f4f0c5a88cf4dfb5f47
linuxlinux>= ea2034416b54700e30371f2ad6517cbb94674083 < 6c6e8fc3c007319981647b410c29bb57750485516c6e8fc3c007319981647b410c29bb5775048551
linuxlinux>= ea2034416b54700e30371f2ad6517cbb94674083 < 3f474c33ebc2e2ca3fcb587d7de4375348f133733f474c33ebc2e2ca3fcb587d7de4375348f13373
linuxlinux>= ea2034416b54700e30371f2ad6517cbb94674083 < 3c2d0de23ae4be22b6c18e8f0915be74d3b5fb213c2d0de23ae4be22b6c18e8f0915be74d3b5fb21
linuxlinux>= ea2034416b54700e30371f2ad6517cbb94674083 < 7ab3fbb01bc6d79091bc375e5235d360cd9b78be7ab3fbb01bc6d79091bc375e5235d360cd9b78be
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.