Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-53043

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-787 Escritura fuera de límites
Fecha de publicación:
24/06/2026
Última modificación:
14/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> ocfs2/dlm: validate qr_numregions in dlm_match_regions()<br /> <br /> Patch series "ocfs2/dlm: fix two bugs in dlm_match_regions()".<br /> <br /> In dlm_match_regions(), the qr_numregions field from a DLM_QUERY_REGION<br /> network message is used to drive loops over the qr_regions buffer without<br /> sufficient validation. This series fixes two issues:<br /> <br /> - Patch 1 adds a bounds check to reject messages where qr_numregions<br /> exceeds O2NM_MAX_REGIONS. The o2net layer only validates message<br /> byte length; it does not constrain field values, so a crafted message<br /> can set qr_numregions up to 255 and trigger out-of-bounds reads past<br /> the 1024-byte qr_regions buffer.<br /> <br /> - Patch 2 fixes an off-by-one in the local-vs-remote comparison loop,<br /> which uses &amp;#39;

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 2.6.37 (incluyendo) 5.10.258 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.11 (incluyendo) 5.15.209 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 5.16 (incluyendo) 6.1.175 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.2 (incluyendo) 6.6.141 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (incluyendo) 6.12.91 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (incluyendo) 6.18.33 (excluyendo)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.19 (incluyendo) 7.0.10 (excluyendo)