« Volver al listado

CVE-2026-80804

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

xfs: restore nofs context unconditionally in xfs_trans_roll

When __xfs_trans_commit() fails in xfs_trans_roll(), the NOFS context is cleared but only restored in the success path. This leaves the error path without nofs protection, causing a circular lock dependency between xfs_nondir_ilock_class and fs_reclaim:

Fix this by moving xfs_trans_set_context() before the error check so that nofs context is always restored on the new transaction.

Detalles técnicos trazas, registros y código del informe original
       CPU0                    CPU1
       ----                    ----
  lock(&xfs_nondir_ilock_class);
                               lock(fs_reclaim);
                               lock(&xfs_nondir_ilock_class);
  lock(fs_reclaim);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80804",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "a1ca658d649a4d8972e2e21ac2625b633217e327",
              "lessThan": "b09198cf90ccf296970b774beea1c1ddb260f94c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a1ca658d649a4d8972e2e21ac2625b633217e327",
              "lessThan": "4d00a39c676274f4071b467e630565ac1e3ae0f2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a1ca658d649a4d8972e2e21ac2625b633217e327",
              "lessThan": "0241ea5fb0fe86d2a673163b2f5815111aadc7f7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/xfs/xfs_trans.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.1",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/xfs/xfs_trans.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:07.397",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0241ea5fb0fe86d2a673163b2f5815111aadc7f7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4d00a39c676274f4071b467e630565ac1e3ae0f2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b09198cf90ccf296970b774beea1c1ddb260f94c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: restore nofs context unconditionally in xfs_trans_roll\n\nWhen __xfs_trans_commit() fails in xfs_trans_roll(), the NOFS context\nis cleared but only restored in the success path.  This leaves the\nerror path without nofs protection, causing a circular lock dependency\nbetween xfs_nondir_ilock_class and fs_reclaim:\n\n       CPU0                    CPU1\n       ----                    ----\n  lock(&xfs_nondir_ilock_class);\n                               lock(fs_reclaim);\n                               lock(&xfs_nondir_ilock_class);\n  lock(fs_reclaim);\n\nFix this by moving xfs_trans_set_context() before the error check so\nthat nofs context is always restored on the new transaction."
    }
  ],
  "lastModified": "2026-09-04T16:18:07.397",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}