Kernel-level vuln in Linux ocfs2 DLM can crash or corrupt nodes in clusters; affects widely used Linux kernel component and can disrupt enterprise infrastructure.
CVE-2026-89495
ocfs2 DLM accepts oversized fields causing heap overflow and kernel panic from cluster peers.
Is CVE-2026-89495 being exploited?
Not confirmed. CVE-2026-89495 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.70% probability of exploitation in the next 30 days.
How severe is CVE-2026-89495?
CVE-2026-89495 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-89495?
Yes. A fix has been recorded for CVE-2026-89495. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-89495 affect?
CVE-2026-89495 affects Linux kernel (ocfs2/o2dlm), Clusters using ocfs2 and o2net DLM domain. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-89495?
Apply kernel ocfs2/o2dlm patches or update to a fixed kernel; restrict/untrust DLM domain membership.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
A cluster node can send malformed DLM messages causing heap out-of-bounds writes or OOB reads that lead to kernel panic (DoS) and may enable remote code execution.
Immediate action required
- affected>= 6714d8e86bf443f6f7af50f9d432025649f091f5 and < f8658ee3327f73bd81c0bcd07cdeb5a8527fac98
- affected>= 6714d8e86bf443f6f7af50f9d432025649f091f5 and < de10cd3b062a5235af754925fcf49beb5a1109d4
- affected>= 6714d8e86bf443f6f7af50f9d432025649f091f5 and < 2487bea2098322669f0563baff53e797486b823f
- affected>= 6714d8e86bf443f6f7af50f9d432025649f091f5 and < ea5b5609305a8437bc955a0834a530c12246d78f
- affected2.6.16
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.