CVE-2026-93269

Summary

In the Linux kernel, the following vulnerability has been resolved:

ext4: fix circular lock dependency in ext4_ext_migrate

Move iput(tmp_inode) after ext4_writepages_up_write() to avoid a circular lock dependency between s_writepages_rwsem and sb_internal (freeze protection).

The deadlock scenario:

CPU0 (EXT4_IOC_MIGRATE) CPU1 (orphan cleanup during mount)


ext4_ext_migrate() ext4_writepages_down_write() s_writepages_rwsem (write) ext4_evict_inode() sb_start_intwrite() [sb_internal] … ext4_writepages() s_writepages_rwsem (read) [BLOCKED] iput(tmp_inode) ext4_evict_inode() sb_start_intwrite() [BLOCKED]

The tmp_inode is a temporary inode with nlink=0 created solely for building the extent tree. Its eviction does not require s_writepages_rwsem protection, so deferring iput() until after releasing the rwsem is safe.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxcb85f4d23f794e24127f3e562cb3b54b0803f456 < 452950461241dfed8b1d32e94b227db38c99c5afaffected
LinuxLinuxcb85f4d23f794e24127f3e562cb3b54b0803f456 < ada23457d4748d6e9c36c6f871fc29a6f558c48caffected
LinuxLinuxcb85f4d23f794e24127f3e562cb3b54b0803f456 < e4223231b6860141813637a6413c2371ae4d6fa8affected
LinuxLinuxcb85f4d23f794e24127f3e562cb3b54b0803f456 < 32f7ab52875ec7f800ca67e7176e5743a84baddfaffected
LinuxLinuxcb85f4d23f794e24127f3e562cb3b54b0803f456 < a897682793eba5de51ee6f3152760374afa629cfaffected
LinuxLinuxeb799e163dc2bc1ea0a4820b66f79d32a5e907dfaffected
LinuxLinuxbcc1eab71a67c46b9e24544ac7923f44444174ceaffected
LinuxLinux8cf20fb73e73a4c4df0328b5297842c5ef34fdd9affected
LinuxLinuxe5d25003d059649e18a249635ed5ca7a7b1de5adaffected
LinuxLinux69f8a7991fd93c49096ddd11574db3e7df238b7baffected
LinuxLinux4.9.215 < 4.10affected
LinuxLinux4.14.172 < 4.15affected
LinuxLinux4.19.107 < 4.20affected
LinuxLinux5.4.23 < 5.5affected
LinuxLinux5.5.7 < 5.6affected
LinuxLinux5.6affected
LinuxLinux0 < 5.6unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References