SB2026090565 - Deadlock in Linux kernel ocfs2
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Deadlock (CVE-ID: CVE-2026-80879)
CWE-ID: CWE-833 - Deadlock
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a circular locking dependency in ocfs2_dio_end_io_write when completing direct I/O writes involving unwritten extents and orphan cleanup. A local user can perform filesystem operations that trigger conflicting lock acquisition to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/137e8b4823a9a11928428d4ec0a0cacb2f50a769
- https://git.kernel.org/stable/c/4273548e418bd935430d35e9d052870f323441f3
- https://git.kernel.org/stable/c/49b34bd3ad69611af03590a23abf2cda9ac1073d
- https://git.kernel.org/stable/c/ae1f3460833d3e427420ab260278ec0e45d68c86
- https://git.kernel.org/stable/c/f0ae0a6ca87dc2d4a789f71cdedb808ba6c16990
- https://git.kernel.org/stable/c/f3dd1e534e9de64669415f8239e0094afecfed78
- https://git.kernel.org/stable/c/ff187c502b39389b0d732cb7050a3db8e5ebfcd6
- https://git.kernel.org/stable/c/ff6f26c58421614b02694ac9d219ac61d924bc68