Deadlock in Linux kernel - CVE-2026-80879
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a circular locking dependency in ocfs2_dio_end_io_write when completing direct I/O writes involving unwritten extents and orphan cleanup. A local user can perform filesystem operations that trigger conflicting lock acquisition to cause a denial of service.
Affected software
How to mitigate CVE-2026-80879
External References
- https://git.kernel.org/stable/c/137e8b4823a9a11928428d4ec0a0cacb2f50a769
- https://git.kernel.org/stable/c/4273548e418bd935430d35e9d052870f323441f3
- https://git.kernel.org/stable/c/49b34bd3ad69611af03590a23abf2cda9ac1073d
- https://git.kernel.org/stable/c/ae1f3460833d3e427420ab260278ec0e45d68c86
- https://git.kernel.org/stable/c/f0ae0a6ca87dc2d4a789f71cdedb808ba6c16990
- https://git.kernel.org/stable/c/f3dd1e534e9de64669415f8239e0094afecfed78
- https://git.kernel.org/stable/c/ff187c502b39389b0d732cb7050a3db8e5ebfcd6
- https://git.kernel.org/stable/c/ff6f26c58421614b02694ac9d219ac61d924bc68