Deadlock in Linux kernel - CVE-2026-68459
Published: August 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in f2fs_balance_fs() gc_merge path when handling filesystem writeback and foreground garbage collection. A local user can trigger filesystem activity that causes a deadlock to cause a denial of service.
Only systems mounted with the gc_merge option are vulnerable.
Affected software
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-nvidia-7.0 (Ubuntu package)
linux-raspi (Ubuntu package)
linux-nvidia-bos (Ubuntu package)
How to mitigate CVE-2026-68459
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-ibm (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
linux-nvidia (Ubuntu package) - update to 7.0.0-1018.18
linux-nvidia-7.0 (Ubuntu package) - update to 7.0.0-1018.18~24.04.1
linux-raspi (Ubuntu package) - update to 7.0.0-1019.19
linux-nvidia-bos (Ubuntu package) - update to 7.0.0-2018.18
External References
- https://git.kernel.org/stable/c/1436031b33fa23ab1ce7df5bc5500093413e8acf
- https://git.kernel.org/stable/c/8071500a8124e5a6d47d901a8d5ffd91743107a1
- https://git.kernel.org/stable/c/89479a27fa4e1e11f378b3724944eabceb84f114
- https://git.kernel.org/stable/c/8b4468ec023d0d1b4669dfb867588997cc03a06b
- https://git.kernel.org/stable/c/aa807064473abd6f2cafe419fb77ea402d3e3104
- https://git.kernel.org/stable/c/b885c7783c19c36c7bf899492a0bffcd68afa8c7
- https://git.kernel.org/stable/c/eb02f218aacb36365e0ca2339cbae81fb05d31a5
Related Security Bulletins
- Deadlock in Linux kernel f2fs
- Ubuntu update for linux-oem-7.0
- Ubuntu update for linux
- Ubuntu update for linux-gcp-7.0
- Ubuntu update for linux-oracle-7.0
- Ubuntu update for linux-azure
- Ubuntu update for linux-azure-7.0
- Ubuntu update for linux-nvidia
- Ubuntu update for linux-nvidia-bos
- Ubuntu update for linux-ibm
- Ubuntu update for linux-raspi
- Ubuntu update for linux-nvidia-7.0