UBUNTU-CVE-2026-53043
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-53043
UBUNTU-CVE-2026-53043
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: validate qr_numregions in dlm_match_regions() Patch series "ocfs2/dlm: fix two bugs in dlm_match_regions()". In dlm_match_regions(), the qr_numregions field from a DLM_QUERY_REGION network message is used to drive loops over the qr_regions buffer without sufficient validation. This series fixes two issues: - Patch 1 adds a bounds check to reject messages where qr_numregions exceeds O2NM_MAX_REGIONS. The o2net layer only validates message byte length; it does not constrain field values, so a crafted message can set qr_numregions up to 255 and trigger out-of-bounds reads past the 1024-byte qr_regions buffer. - Patch 2 fixes an off-by-one in the local-vs-remote comparison loop, which uses '<=' instead of '<', reading one entry past the valid range even when qr_numregions is within bounds. This patch (of 2): The qr_numregions field from a DLM_QUERY_REGION network message is used directly as loop bounds in dlm_match_regions() without checking against O2NM_MAX_REGIONS. Since qr_regions is sized for at most O2NM_MAX_REGIONS (32) entries, a crafted message with qr_numregions > 32 causes out-of-bounds reads past the qr_regions buffer. Add a bounds check for qr_numregions before entering the loops.
References: https://ubuntu.com/security/CVE-2026-53043, https://www.cve.org/CVERecord?id=CVE-2026-53043, https://git.kernel.org/linus/7ab3fbb01bc6d79091bc375e5235d360cd9b78be, https://ubuntu.com/security/notices/USN-8566-1, https://ubuntu.com/security/notices/USN-8568-1, https://ubuntu.com/security/notices/USN-8569-1, https://ubuntu.com/security/notices/USN-8567-1, https://ubuntu.com/security/notices/USN-8574-1, https://ubuntu.com/security/notices/USN-8575-1, https://ubuntu.com/security/notices/USN-8576-1, https://ubuntu.com/security/notices/USN-8593-1, https://ubuntu.com/security/notices/USN-8574-2, https://ubuntu.com/security/notices/USN-8595-1, https://ubuntu.com/security/notices/USN-8596-1, https://ubuntu.com/security/notices/USN-8575-2, https://ubuntu.com/security/notices/USN-8576-2, https://ubuntu.com/security/notices/USN-8603-1, https://ubuntu.com/security/notices/USN-8595-2, https://ubuntu.com/security/notices/USN-8606-1, https://ubuntu.com/security/notices/USN-8607-1, https://ubuntu.com/security/notices/USN-8608-1, https://ubuntu.com/security/notices/USN-8609-1, https://ubuntu.com/security/notices/USN-8575-3, https://ubuntu.com/security/notices/USN-8610-1, https://ubuntu.com/security/notices/USN-8618-1, https://ubuntu.com/security/notices/USN-8574-3, https://ubuntu.com/security/notices/USN-8595-3, https://ubuntu.com/security/notices/USN-8619-1, https://ubuntu.com/security/notices/USN-8620-1, https://ubuntu.com/security/notices/USN-8620-2, https://ubuntu.com/security/notices/USN-8620-3, https://ubuntu.com/security/notices/USN-8620-4, https://ubuntu.com/security/notices/USN-8644-1, https://ubuntu.com/security/notices/USN-8645-1, https://ubuntu.com/security/notices/USN-8646-1, https://ubuntu.com/security/notices/USN-8644-2, https://ubuntu.com/security/notices/USN-8663-1, https://ubuntu.com/security/notices/USN-8664-1, https://ubuntu.com/security/notices/USN-8665-1, https://ubuntu.com/security/notices/USN-8668-1, https://ubuntu.com/security/notices/USN-8644-3, https://ubuntu.com/security/notices/USN-8714-1, https://ubuntu.com/security/notices/USN-8715-1, https://ubuntu.com/security/notices/USN-8714-2, https://ubuntu.com/security/notices/USN-8725-1, https://ubuntu.com/security/notices/USN-8728-1, https://ubuntu.com/security/notices/USN-8748-1, https://ubuntu.com/security/notices/USN-8714-3, https://ubuntu.com/security/notices/USN-8715-2, https://ubuntu.com/security/notices/USN-8725-2, https://ubuntu.com/security/notices/USN-8668-2, https://ubuntu.com/security/notices/USN-8728-2
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/linux?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
