CVE-2026-80804
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
xfs: restore nofs context unconditionally in xfs_trans_roll
When __xfs_trans_commit() fails in xfs_trans_roll(), the NOFS context is cleared but only restored in the success path. This leaves the error path without nofs protection, causing a circular lock dependency between xfs_nondir_ilock_class and fs_reclaim:
CPU0 CPU1
---- ----
lock(&xfs_nondir_ilock_class); lock(fs_reclaim); lock(&xfs_nondir_ilock_class); lock(fs_reclaim);
Fix this by moving xfs_trans_set_context() before the error check so that nofs context is always restored on the new transaction.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | a1ca658d649a4d8972e2e21ac2625b633217e327 < b09198cf90ccf296970b774beea1c1ddb260f94c | affected |
| Linux | Linux | a1ca658d649a4d8972e2e21ac2625b633217e327 < 4d00a39c676274f4071b467e630565ac1e3ae0f2 | affected |
| Linux | Linux | a1ca658d649a4d8972e2e21ac2625b633217e327 < 0241ea5fb0fe86d2a673163b2f5815111aadc7f7 | affected |
| Linux | Linux | 7.0 | affected |
| Linux | Linux | 0 < 7.0 | unaffected |
| Linux | Linux | 7.1.11 <= 7.1.* | unaffected |
| Linux | Linux | 7.2.1 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/b09198cf90ccf296970b774beea1c1ddb260f94c
- https://git.kernel.org/stable/c/4d00a39c676274f4071b467e630565ac1e3ae0f2
- https://git.kernel.org/stable/c/0241ea5fb0fe86d2a673163b2f5815111aadc7f7
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.