Deadlock in Linux kernel - CVE-2026-68459
Published: August 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper locking in f2fs_balance_fs() gc_merge path when handling filesystem writeback and foreground garbage collection. A local user can trigger filesystem activity that causes a deadlock to cause a denial of service.
Only systems mounted with the gc_merge option are vulnerable.
Affected software
How to mitigate CVE-2026-68459
External References
- https://git.kernel.org/stable/c/1436031b33fa23ab1ce7df5bc5500093413e8acf
- https://git.kernel.org/stable/c/8071500a8124e5a6d47d901a8d5ffd91743107a1
- https://git.kernel.org/stable/c/89479a27fa4e1e11f378b3724944eabceb84f114
- https://git.kernel.org/stable/c/8b4468ec023d0d1b4669dfb867588997cc03a06b
- https://git.kernel.org/stable/c/aa807064473abd6f2cafe419fb77ea402d3e3104
- https://git.kernel.org/stable/c/b885c7783c19c36c7bf899492a0bffcd68afa8c7
- https://git.kernel.org/stable/c/eb02f218aacb36365e0ca2339cbae81fb05d31a5