« Volver al listado

CVE-2026-80879

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write

A circular locking dependency involves INODE_ALLOC_SYSTEM_INODE, EXTENT_ALLOC_SYSTEM_INODE, and ORPHAN_DIR_SYSTEM_INODE.

1. ocfs2_mknod() acquires INODE_ALLOC then EXTENT_ALLOC.

Break the cycle in ocfs2_dio_end_io_write() by freeing the allocation contexts (releasing EXTENT_ALLOC) before acquiring ORPHAN_DIR.

WARNING: possible circular locking dependency detected ------------------------------------------------------ is trying to acquire lock: ffff8881e78b33a0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}, at: ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299

Leer descripción completaMostrar menos

but task is already holding lock: ffff8881e78b4fa0 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}, at: ocfs2_evict_inode+0xe97/0x43b0 fs/ocfs2/inode.c:1299

the existing dependency chain (in reverse order) is:

Possible unsafe locking scenario:

*** DEADLOCK ***

Detalles técnicos trazas, registros y código del informe original
2. ocfs2_dio_end_io_write() acquires EXTENT_ALLOC for unwritten
   extents, then ORPHAN_DIR via ocfs2_del_inode_from_orphan() while still
   holding EXTENT_ALLOC.

3. ocfs2_wipe_inode() acquires ORPHAN_DIR then INODE_ALLOC via
   ocfs2_remove_inode.

-> #2 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}:
       inode_lock include/linux/fs.h:1029 [inline]
       ocfs2_del_inode_from_orphan+0x12e/0x7a0 fs/ocfs2/namei.c:2728
       ocfs2_dio_end_io+0xf9c/0x1370 fs/ocfs2/aops.c:2418
       dio_complete+0x25b/0x790 fs/direct-io.c:281

-> #1 (&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:
       inode_lock include/linux/fs.h:1029 [inline]
       ocfs2_reserve_suballoc_bits+0x16d/0x4840 fs/ocfs2/suballoc.c:882
       ocfs2_reserve_new_metadata_blocks+0x415/0x9a0
       fs/ocfs2/suballoc.c:1078
       ocfs2_mknod+0x10f3/0x2260 fs/ocfs2/namei.c:351

-> #0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:
       __lock_acquire+0x15a5/0x2cf0 kernel/locking/lockdep.c:5237
       lock_acquire+0x106/0x350 kernel/locking/lockdep.c:5868
       down_write+0x96/0x200 kernel/locking/rwsem.c:1625
       inode_lock include/linux/fs.h:1029 [inline]
       ocfs2_remove_inode fs/ocfs2/inode.c:733 [inline]
       ocfs2_wipe_inode fs/ocfs2/inode.c:896 [inline]
       ocfs2_delete_inode fs/ocfs2/inode.c:1157 [inline]
       ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299

Chain exists of:
  &ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE] -->
  &ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE] -->
  &ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]

       CPU0                    CPU1
       ----                    ----
  lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);
                               lock(&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]);
                               lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);
  lock(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]);

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80879",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "97c03c0e9f73a5049794b3c69ee60fb5e8b0ebd8",
              "lessThan": "f0ae0a6ca87dc2d4a789f71cdedb808ba6c16990",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1e99bb19994246514d63e656492904176f9d5edd",
              "lessThan": "137e8b4823a9a11928428d4ec0a0cacb2f50a769",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "91e05ac2336d00d5b99fc774be4bd50039084796",
              "lessThan": "4273548e418bd935430d35e9d052870f323441f3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "886f97fa59d0bbfa9859fb1a66dd9e014b522d89",
              "lessThan": "49b34bd3ad69611af03590a23abf2cda9ac1073d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ea5bb1d20da756e4f41a48dad42b2e7d6e73f71e",
              "lessThan": "ff187c502b39389b0d732cb7050a3db8e5ebfcd6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3c636a3edca9c3f180b3079f94fe7e115730d9c6",
              "lessThan": "ae1f3460833d3e427420ab260278ec0e45d68c86",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d647c5b2fbf81560818dacade360abc8c00a9665",
              "lessThan": "f3dd1e534e9de64669415f8239e0094afecfed78",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d647c5b2fbf81560818dacade360abc8c00a9665",
              "lessThan": "ff6f26c58421614b02694ac9d219ac61d924bc68",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "069c3fb310e9336cf48cfdf8748a32c29fd0193d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.258",
              "lessThan": "5.10.261",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.209",
              "lessThan": "5.15.212",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.175",
              "lessThan": "6.1.178",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.140",
              "lessThan": "6.6.145",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.86",
              "lessThan": "6.12.97",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.27",
              "lessThan": "6.18.40",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "7.0.4",
              "lessThan": "7.1",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/ocfs2/aops.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.261",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.212",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/ocfs2/aops.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T17:17:00.080",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/137e8b4823a9a11928428d4ec0a0cacb2f50a769",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4273548e418bd935430d35e9d052870f323441f3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/49b34bd3ad69611af03590a23abf2cda9ac1073d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ae1f3460833d3e427420ab260278ec0e45d68c86",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f0ae0a6ca87dc2d4a789f71cdedb808ba6c16990",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f3dd1e534e9de64669415f8239e0094afecfed78",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ff187c502b39389b0d732cb7050a3db8e5ebfcd6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ff6f26c58421614b02694ac9d219ac61d924bc68",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix circular locking dependency in ocfs2_dio_end_io_write\n\nA circular locking dependency involves INODE_ALLOC_SYSTEM_INODE,\nEXTENT_ALLOC_SYSTEM_INODE, and ORPHAN_DIR_SYSTEM_INODE.\n\n1. ocfs2_mknod() acquires INODE_ALLOC then EXTENT_ALLOC.\n\n2. ocfs2_dio_end_io_write() acquires EXTENT_ALLOC for unwritten\n   extents, then ORPHAN_DIR via ocfs2_del_inode_from_orphan() while still\n   holding EXTENT_ALLOC.\n\n3. ocfs2_wipe_inode() acquires ORPHAN_DIR then INODE_ALLOC via\n   ocfs2_remove_inode.\n\nBreak the cycle in ocfs2_dio_end_io_write() by freeing the allocation\ncontexts (releasing EXTENT_ALLOC) before acquiring ORPHAN_DIR.\n\nWARNING: possible circular locking dependency detected\n------------------------------------------------------\nis trying to acquire lock:\nffff8881e78b33a0\n(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}, at:\nocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299\n\nbut task is already holding lock:\nffff8881e78b4fa0\n(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}, at:\nocfs2_evict_inode+0xe97/0x43b0 fs/ocfs2/inode.c:1299\n\nthe existing dependency chain (in reverse order) is:\n\n-> #2 (&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]){+.+.}-{4:4}:\n       inode_lock include/linux/fs.h:1029 [inline]\n       ocfs2_del_inode_from_orphan+0x12e/0x7a0 fs/ocfs2/namei.c:2728\n       ocfs2_dio_end_io+0xf9c/0x1370 fs/ocfs2/aops.c:2418\n       dio_complete+0x25b/0x790 fs/direct-io.c:281\n\n-> #1 (&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:\n       inode_lock include/linux/fs.h:1029 [inline]\n       ocfs2_reserve_suballoc_bits+0x16d/0x4840 fs/ocfs2/suballoc.c:882\n       ocfs2_reserve_new_metadata_blocks+0x415/0x9a0\n       fs/ocfs2/suballoc.c:1078\n       ocfs2_mknod+0x10f3/0x2260 fs/ocfs2/namei.c:351\n\n-> #0 (&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]){+.+.}-{4:4}:\n       __lock_acquire+0x15a5/0x2cf0 kernel/locking/lockdep.c:5237\n       lock_acquire+0x106/0x350 kernel/locking/lockdep.c:5868\n       down_write+0x96/0x200 kernel/locking/rwsem.c:1625\n       inode_lock include/linux/fs.h:1029 [inline]\n       ocfs2_remove_inode fs/ocfs2/inode.c:733 [inline]\n       ocfs2_wipe_inode fs/ocfs2/inode.c:896 [inline]\n       ocfs2_delete_inode fs/ocfs2/inode.c:1157 [inline]\n       ocfs2_evict_inode+0x1539/0x43b0 fs/ocfs2/inode.c:1299\n\nChain exists of:\n  &ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE] -->\n  &ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE] -->\n  &ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]\n\n Possible unsafe locking scenario:\n\n       CPU0                    CPU1\n       ----                    ----\n  lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);\n                               lock(&ocfs2_sysfile_lock_key[EXTENT_ALLOC_SYSTEM_INODE]);\n                               lock(&ocfs2_sysfile_lock_key[ORPHAN_DIR_SYSTEM_INODE]);\n  lock(&ocfs2_sysfile_lock_key[INODE_ALLOC_SYSTEM_INODE]);\n\n *** DEADLOCK ***"
    }
  ],
  "lastModified": "2026-09-04T17:17:00.080",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}