Improper locking in Linux kernel - CVE-2026-53049
Published: June 25, 2026
Vulnerability identifier: #VU135301
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-53049
CWE-ID: CWE-667
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in gfs2_logd() and log flushing functions in the gfs2 log subsystem when handling concurrent transactions. A local user can trigger concurrent log flush activity to cause a denial of service.
How to mitigate CVE-2026-53049
Install security update from vendor's repository.
Sources
- https://git.kernel.org/stable/c/3b28eb75afe520972bacc833850c2b30aa0824cd
- https://git.kernel.org/stable/c/49d9be0722da3a4a893ba905720cba1921834ec3
- https://git.kernel.org/stable/c/98e8bf249c790d56de1abc4a5f8bd68035a00921
- https://git.kernel.org/stable/c/bf5fcd9c37c2546beaf7b401d31aefd89017dc3d
- https://git.kernel.org/stable/c/ca95342cb1b39062a03c115830286f0a426053d5
- https://git.kernel.org/stable/c/f2f225cf505ac016132ded21690f3ba0a080a4e8
- https://git.kernel.org/stable/c/fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8