{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ocfs2/cluster: keep heartbeat local node stable  o2nm_node_local_store() handles local=0 by stopping o2net and setting cl_local_node to O2NM_INVALID_NODE_NUM, but it leaves cl_has_local set.  That stale state makes o2nm_this_node() return 255, blocks a later local=1 attempt with -EBUSY, and can feed 255 to heartbeat users that call o2nm_this_node() dynamically.  Clearing cl_has_local is required when the local node is reset.  But heartbeat threads can still be running at that point.  They pin the local node config item at startup, yet o2hb_do_disk_heartbeat() and thread teardown re-read o2nm_this_node() for the local slot and for o2nm_undepend_this_node().  Once local=0 has cleared the live local-node state, those dynamic reads return O2NM_MAX_NODES, which is also the invalid node number 255.  Store the local node number in the heartbeat region when the region starts.  Use that stable node for heartbeat slot writes/checks, negotiation messages, and the final configfs undepend.  Stop the heartbeat loop when the current local node no longer matches the stored node, and clear cl_has_local together with cl_local_node in the local=0 path so nodemanager state matches node removal.  Validation reproduced this kernel report: KASAN slab-out-of-bounds in o2hb_do_disk_heartbeat+0x372/0xb30 RIP: 0010:memset+0xf/0x20 Read of size 8 Call trace:   dump_stack_lvl+0x66/0xa0   print_report+0xd0/0x630   o2hb_do_disk_heartbeat+0x372/0xb30 (fs/ocfs2/cluster/heartbeat.c:1079)   srso_alias_return_thunk+0x5/0xfbef5   __virt_addr_valid+0x188/0x2f0   kasan_report+0xe4/0x120   o2hb_do_disk_heartbeat+0x5/0xb30 (fs/ocfs2/cluster/heartbeat.c:1079)   o2hb_thread+0x14e/0x770   kthread_affine_node+0x139/0x180   lockdep_hardirqs_on_prepare+0xda/0x190   trace_hardirqs_on+0x18/0x130   kthread+0x19d/0x1e0   ret_from_fork+0x37a/0x4d0   __switch_to+0x2d5/0x6f0   ret_from_fork_asm+0x1a/0x30",
  "id": "DEBIAN-CVE-2026-90322",
  "modified": "2026-09-18T04:47:36.709681787Z",
  "published": "2026-09-17T17:17:30.173Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-90322"
    }
  ],
  "upstream": [
    "CVE-2026-90322"
  ]
}