Kernel off-by-one in ocfs2/dlm may allow memory read; Linux kernel ubiquity across industries; critical if exploited.
CVE-2026-53309
Local kernel off-by-one bug in ocfs2/dlm region compare.
Is CVE-2026-53309 being exploited?
Not confirmed. CVE-2026-53309 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.40% probability of exploitation in the next 30 days.
How severe is CVE-2026-53309?
CVE-2026-53309 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-53309?
Yes. A fix has been recorded for CVE-2026-53309. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-53309 affect?
CVE-2026-53309 affects Linux kernel (ocfs2/dlm). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-53309?
Apply patched kernel with ocfs2/dlm fix
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local attacker can read memory beyond qr_regions, risking info disclosure or kernel instability.
Patch when possible
- affected>= ea2034416b54700e30371f2ad6517cbb94674083 and < 760ab35040aca8399021fdb9ff1db1089feb7194
- affected>= ea2034416b54700e30371f2ad6517cbb94674083 and < c60a2710b73838d250cda57344c049b89abc5d52
- affected>= ea2034416b54700e30371f2ad6517cbb94674083 and < 2a0673836f019e7c032acbf48d022d5ccf02a845
- affected>= ea2034416b54700e30371f2ad6517cbb94674083 and < 819d8ebad3200a53de99bd7e297bc428e41ced54
- affected>= ea2034416b54700e30371f2ad6517cbb94674083 and < d5403ae28085761d58b555645bc7d5feadb10073
- affected>= ea2034416b54700e30371f2ad6517cbb94674083 and < 1fb7f356547d9688822315cd2b205ff0bd5429b4
- affected>= ea2034416b54700e30371f2ad6517cbb94674083 and < 426cd8eedac89b86148d4478990eeef16e8a2520
- affected>= ea2034416b54700e30371f2ad6517cbb94674083 and < 01b61e8dda9b0fdb0d4cda43de25f4e390554d7b
- affected2.6.37
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.