Junglewise Threat Intelligence

CVE-2026-53309: Linux Kernel off-by-one error in ocfs2/dlm dlm_match_regions

CVE-2026-53309 · Severity: info · CVSS 0 · Published 2026-06-26

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's OCFS2 file system component, which is used for managing shared storage in clustered environments. An error in how the system compares memory regions could allow the software to read data outside of its intended boundaries. While typically resulting in a system crash or instability, such flaws can sometimes be leveraged to access sensitive information or disrupt cluster operations.

Technical details

An off-by-one vulnerability exists in the dlm_match_regions() function within fs/ocfs2/dlm/dlmdomain.c of the Linux kernel. The local-vs-remote region comparison loop incorrectly used a '<=' operator instead of '<' when iterating through qr_regions, leading to a read one entry past the valid array range. This out-of-bounds read occurs during the processing of DLM_QUERY_REGION messages. An attacker could potentially exploit this to cause a kernel oops (denial of service) or leak sensitive memory contents from the slab. The issue has been patched across multiple stable kernel branches including 5.10.y, 5.15.y, 6.1.y, 6.6.y, and later.

Affected products

  • Linux Linux 2.6.37 to 6.13

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory

References