PT-2026-94670 · Linux · Linux Kernel

CVE-2026-90322

·

Published

2026-09-17

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the OCFS2 cluster component where the o2nm node local store() function fails to clear the cl has local variable when handling local=0. This creates a stale state that causes o2nm this node() to return an invalid node number (255), which can block subsequent attempts to set local=1 with an -EBUSY error and provide incorrect data to heartbeat users.
Furthermore, heartbeat threads that re-read o2nm this node() during execution or teardown may receive the invalid node number O2NM MAX NODES (255) after the local node state has been cleared. This can lead to a KASAN slab-out-of-bounds error within the o2hb do disk heartbeat() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-102906
CVE-2026-90322
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel