Infinite loop in Linux kernel - CVE-2026-80808
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an infinite retry loop in ext4_xattr_block_set() when reusing a saturated extended attribute cache entry on a corrupted filesystem. A local user can trigger repeated selection of the unusable cache entry to cause a denial of service.
Concurrent rmdir callers can remain blocked while the spinning task holds the parent directory's i_rwsem.
Affected software
How to mitigate CVE-2026-80808
External References
- https://git.kernel.org/stable/c/119a2f053242ed75bdd2ebc95baf3ae7db6ccacf
- https://git.kernel.org/stable/c/4902a5cba21aeaf91e6b29e20e0967a5f6abdcd9
- https://git.kernel.org/stable/c/54b6bd40898de7906acb2bccc9a96d1b8e6b4323
- https://git.kernel.org/stable/c/55ee6533c1db7f7656fa8dd19637f3f8b8c08dc5
- https://git.kernel.org/stable/c/61631352a5b405c89be579de00903b72e6888aa4
- https://git.kernel.org/stable/c/8865cd664484517703df5c18a965dc3227572b87
- https://git.kernel.org/stable/c/889ec86464d261f026f6c334040cfc6c58c99d58
- https://git.kernel.org/stable/c/a40c45268f4358207aa9c53764fed2e05f62986a
- https://git.kernel.org/stable/c/dbd4aea175ad3c46436acb251e817b4374628072