CVE-2026-80879
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write
A circular locking dependency involves INODE_ALLOC_SYSTEM_INODE, EXTENT_ALLOC_SYSTEM_INODE, and ORPHAN_DIR_SYSTEM_INODE.
1. ocfs2_mknod() acquires INODE_ALLOC then EXTENT_ALLOC.
Break the cycle in ocfs2_dio_end_io_write() by freeing the allocation contexts (releasing EXTENT_ALLOC) before acquiring ORPHAN_DIR.
WARNING: possible circular locking dependency detected ------------------------------------------------------ is trying to acquire lock: ffff8881e78b33a0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}, at: ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299
Leer descripción completaMostrar menos
but task is already holding lock: ffff8881e78b4fa0 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}, at: ocfs2_evict_inode+0xe97/0x43b0 fs/ocfs2/inode.c:1299
the existing dependency chain (in reverse order) is:
Possible unsafe locking scenario:
*** DEADLOCK ***
Detalles técnicos trazas, registros y código del informe original
2. ocfs2_dio_end_io_write() acquires EXTENT_ALLOC for unwritten
extents, then ORPHAN_DIR via ocfs2_del_inode_from_orphan() while still
holding EXTENT_ALLOC.
3. ocfs2_wipe_inode() acquires ORPHAN_DIR then INODE_ALLOC via
ocfs2_remove_inode.
-> #2 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}:
inode_lock include/linux/fs.h:1029 [inline]
ocfs2_del_inode_from_orphan+0x12e/0x7a0 fs/ocfs2/namei.c:2728
ocfs2_dio_end_io+0xf9c/0x1370 fs/ocfs2/aops.c:2418
dio_complete+0x25b/0x790 fs/direct-io.c:281
-> #1 (&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:
inode_lock include/linux/fs.h:1029 [inline]
ocfs2_reserve_suballoc_bits+0x16d/0x4840 fs/ocfs2/suballoc.c:882
ocfs2_reserve_new_metadata_blocks+0x415/0x9a0
fs/ocfs2/suballoc.c:1078
ocfs2_mknod+0x10f3/0x2260 fs/ocfs2/namei.c:351
-> #0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:
__lock_acquire+0x15a5/0x2cf0 kernel/locking/lockdep.c:5237
lock_acquire+0x106/0x350 kernel/locking/lockdep.c:5868
down_write+0x96/0x200 kernel/locking/rwsem.c:1625
inode_lock include/linux/fs.h:1029 [inline]
ocfs2_remove_inode fs/ocfs2/inode.c:733 [inline]
ocfs2_wipe_inode fs/ocfs2/inode.c:896 [inline]
ocfs2_delete_inode fs/ocfs2/inode.c:1157 [inline]
ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299
Chain exists of:
&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE] -->
&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE] -->
&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]
CPU0 CPU1
---- ----
lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);
lock(&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]);
lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);
lock(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]);CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/137e8b4823a9a11928428d4ec0a0cacb2f50a769
- https://git.kernel.org/stable/c/4273548e418bd935430d35e9d052870f323441f3
- https://git.kernel.org/stable/c/49b34bd3ad69611af03590a23abf2cda9ac1073d
- https://git.kernel.org/stable/c/ae1f3460833d3e427420ab260278ec0e45d68c86
- https://git.kernel.org/stable/c/f0ae0a6ca87dc2d4a789f71cdedb808ba6c16990
- https://git.kernel.org/stable/c/f3dd1e534e9de64669415f8239e0094afecfed78
- https://git.kernel.org/stable/c/ff187c502b39389b0d732cb7050a3db8e5ebfcd6
- https://git.kernel.org/stable/c/ff6f26c58421614b02694ac9d219ac61d924bc68
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80879",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "97c03c0e9f73a5049794b3c69ee60fb5e8b0ebd8",
"lessThan": "f0ae0a6ca87dc2d4a789f71cdedb808ba6c16990",
"versionType": "git"
},
{
"status": "affected",
"version": "1e99bb19994246514d63e656492904176f9d5edd",
"lessThan": "137e8b4823a9a11928428d4ec0a0cacb2f50a769",
"versionType": "git"
},
{
"status": "affected",
"version": "91e05ac2336d00d5b99fc774be4bd50039084796",
"lessThan": "4273548e418bd935430d35e9d052870f323441f3",
"versionType": "git"
},
{
"status": "affected",
"version": "886f97fa59d0bbfa9859fb1a66dd9e014b522d89",
"lessThan": "49b34bd3ad69611af03590a23abf2cda9ac1073d",
"versionType": "git"
},
{
"status": "affected",
"version": "ea5bb1d20da756e4f41a48dad42b2e7d6e73f71e",
"lessThan": "ff187c502b39389b0d732cb7050a3db8e5ebfcd6",
"versionType": "git"
},
{
"status": "affected",
"version": "3c636a3edca9c3f180b3079f94fe7e115730d9c6",
"lessThan": "ae1f3460833d3e427420ab260278ec0e45d68c86",
"versionType": "git"
},
{
"status": "affected",
"version": "d647c5b2fbf81560818dacade360abc8c00a9665",
"lessThan": "f3dd1e534e9de64669415f8239e0094afecfed78",
"versionType": "git"
},
{
"status": "affected",
"version": "d647c5b2fbf81560818dacade360abc8c00a9665",
"lessThan": "ff6f26c58421614b02694ac9d219ac61d924bc68",
"versionType": "git"
},
{
"status": "affected",
"version": "069c3fb310e9336cf48cfdf8748a32c29fd0193d",
"versionType": "git"
},
{
"status": "affected",
"version": "5.10.258",
"lessThan": "5.10.261",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.15.209",
"lessThan": "5.15.212",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.1.175",
"lessThan": "6.1.178",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.140",
"lessThan": "6.6.145",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.12.86",
"lessThan": "6.12.97",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.18.27",
"lessThan": "6.18.40",
"versionType": "semver"
},
{
"status": "affected",
"version": "7.0.4",
"lessThan": "7.1",
"versionType": "semver"
}
],
"programFiles": [
"fs/ocfs2/aops.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "7.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/ocfs2/aops.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-04T17:17:00.080",
"references": [
{
"url": "https://git.kernel.org/stable/c/137e8b4823a9a11928428d4ec0a0cacb2f50a769",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4273548e418bd935430d35e9d052870f323441f3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/49b34bd3ad69611af03590a23abf2cda9ac1073d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ae1f3460833d3e427420ab260278ec0e45d68c86",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f0ae0a6ca87dc2d4a789f71cdedb808ba6c16990",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f3dd1e534e9de64669415f8239e0094afecfed78",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ff187c502b39389b0d732cb7050a3db8e5ebfcd6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ff6f26c58421614b02694ac9d219ac61d924bc68",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix circular locking dependency in ocfs2_dio_end_io_write\n\nA circular locking dependency involves INODE_ALLOC_SYSTEM_INODE,\nEXTENT_ALLOC_SYSTEM_INODE, and ORPHAN_DIR_SYSTEM_INODE.\n\n1. ocfs2_mknod() acquires INODE_ALLOC then EXTENT_ALLOC.\n\n2. ocfs2_dio_end_io_write() acquires EXTENT_ALLOC for unwritten\n extents, then ORPHAN_DIR via ocfs2_del_inode_from_orphan() while still\n holding EXTENT_ALLOC.\n\n3. ocfs2_wipe_inode() acquires ORPHAN_DIR then INODE_ALLOC via\n ocfs2_remove_inode.\n\nBreak the cycle in ocfs2_dio_end_io_write() by freeing the allocation\ncontexts (releasing EXTENT_ALLOC) before acquiring ORPHAN_DIR.\n\nWARNING: possible circular locking dependency detected\n------------------------------------------------------\nis trying to acquire lock:\nffff8881e78b33a0\n(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}, at:\nocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299\n\nbut task is already holding lock:\nffff8881e78b4fa0\n(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}, at:\nocfs2_evict_inode+0xe97/0x43b0 fs/ocfs2/inode.c:1299\n\nthe existing dependency chain (in reverse order) is:\n\n-> #2 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}:\n inode_lock include/linux/fs.h:1029 [inline]\n ocfs2_del_inode_from_orphan+0x12e/0x7a0 fs/ocfs2/namei.c:2728\n ocfs2_dio_end_io+0xf9c/0x1370 fs/ocfs2/aops.c:2418\n dio_complete+0x25b/0x790 fs/direct-io.c:281\n\n-> #1 (&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:\n inode_lock include/linux/fs.h:1029 [inline]\n ocfs2_reserve_suballoc_bits+0x16d/0x4840 fs/ocfs2/suballoc.c:882\n ocfs2_reserve_new_metadata_blocks+0x415/0x9a0\n fs/ocfs2/suballoc.c:1078\n ocfs2_mknod+0x10f3/0x2260 fs/ocfs2/namei.c:351\n\n-> #0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:\n __lock_acquire+0x15a5/0x2cf0 kernel/locking/lockdep.c:5237\n lock_acquire+0x106/0x350 kernel/locking/lockdep.c:5868\n down_write+0x96/0x200 kernel/locking/rwsem.c:1625\n inode_lock include/linux/fs.h:1029 [inline]\n ocfs2_remove_inode fs/ocfs2/inode.c:733 [inline]\n ocfs2_wipe_inode fs/ocfs2/inode.c:896 [inline]\n ocfs2_delete_inode fs/ocfs2/inode.c:1157 [inline]\n ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299\n\nChain exists of:\n &ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE] -->\n &ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE] -->\n &ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);\n lock(&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]);\n lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);\n lock(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]);\n\n *** DEADLOCK ***"
}
],
"lastModified": "2026-09-04T17:17:00.080",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}