CVE-2026-93269
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
ext4: fix circular lock dependency in ext4_ext_migrate
Move iput(tmp_inode) after ext4_writepages_up_write() to avoid a circular lock dependency between s_writepages_rwsem and sb_internal (freeze protection).
The deadlock scenario:
CPU0 (EXT4_IOC_MIGRATE) CPU1 (orphan cleanup during mount)
ext4_ext_migrate() ext4_writepages_down_write() s_writepages_rwsem (write) ext4_evict_inode() sb_start_intwrite() [sb_internal] … ext4_writepages() s_writepages_rwsem (read) [BLOCKED] iput(tmp_inode) ext4_evict_inode() sb_start_intwrite() [BLOCKED]
The tmp_inode is a temporary inode with nlink=0 created solely for building the extent tree. Its eviction does not require s_writepages_rwsem protection, so deferring iput() until after releasing the rwsem is safe.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | cb85f4d23f794e24127f3e562cb3b54b0803f456 < 452950461241dfed8b1d32e94b227db38c99c5af | affected |
| Linux | Linux | cb85f4d23f794e24127f3e562cb3b54b0803f456 < ada23457d4748d6e9c36c6f871fc29a6f558c48c | affected |
| Linux | Linux | cb85f4d23f794e24127f3e562cb3b54b0803f456 < e4223231b6860141813637a6413c2371ae4d6fa8 | affected |
| Linux | Linux | cb85f4d23f794e24127f3e562cb3b54b0803f456 < 32f7ab52875ec7f800ca67e7176e5743a84baddf | affected |
| Linux | Linux | cb85f4d23f794e24127f3e562cb3b54b0803f456 < a897682793eba5de51ee6f3152760374afa629cf | affected |
| Linux | Linux | eb799e163dc2bc1ea0a4820b66f79d32a5e907df | affected |
| Linux | Linux | bcc1eab71a67c46b9e24544ac7923f44444174ce | affected |
| Linux | Linux | 8cf20fb73e73a4c4df0328b5297842c5ef34fdd9 | affected |
| Linux | Linux | e5d25003d059649e18a249635ed5ca7a7b1de5ad | affected |
| Linux | Linux | 69f8a7991fd93c49096ddd11574db3e7df238b7b | affected |
| Linux | Linux | 4.9.215 < 4.10 | affected |
| Linux | Linux | 4.14.172 < 4.15 | affected |
| Linux | Linux | 4.19.107 < 4.20 | affected |
| Linux | Linux | 5.4.23 < 5.5 | affected |
| Linux | Linux | 5.5.7 < 5.6 | affected |
| Linux | Linux | 5.6 | affected |
| Linux | Linux | 0 < 5.6 | unaffected |
| Linux | Linux | 6.6.157 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.52 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.6 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/452950461241dfed8b1d32e94b227db38c99c5af
- https://git.kernel.org/stable/c/ada23457d4748d6e9c36c6f871fc29a6f558c48c
- https://git.kernel.org/stable/c/e4223231b6860141813637a6413c2371ae4d6fa8
- https://git.kernel.org/stable/c/32f7ab52875ec7f800ca67e7176e5743a84baddf
- https://git.kernel.org/stable/c/a897682793eba5de51ee6f3152760374afa629cf
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.