« Volver al listado

CVE-2026-80855

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

fuse: fix invalidate lock leak on open O_TRUNC DAX failure

fuse_open() takes filemap_invalidate_lock() for a DAX truncate (dax_truncate = true) and releases it before the out_inode_unlock label. But when fuse_dax_break_layouts() fails, the goto out_inode_unlock skips the unlock and leaks the rwsem, so any later fault or truncate on the file stalls on the stale lock.

fuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal interrupts the wait for busy DAX pages to drain:

Fix this by moving filemap_invalidate_unlock() below the label so that all error paths release the lock, and rename the label to out_unlock as it now covers more than just the inode lock.

Detalles técnicos trazas, registros y código del informe original
  open("file", O_RDWR | O_TRUNC)
  └─ fuse_open()
     ├─ filemap_invalidate_lock()        # dax_truncate
     └─ fuse_dax_break_layouts()
        └─ dax_break_layout()
           └─ wait_page_idle()           # TASK_INTERRUPTIBLE
              └─ fuse_wait_dax_page()    # unlock, schedule, re-lock
                 └─ signal → -ERESTARTSYS
     goto out_inode_unlock               # <- lock leaked

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80855",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d58366aab86854217b81679d1a9dcd54a2edfc2a",
              "lessThan": "1b04d80a27d317064cce2307472f5bef9975bc50",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
              "lessThan": "a61524da59a2f5ac9c8de23ff98b30da769ab144",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
              "lessThan": "dcf30a56624c2a0cfab1bada5b1ca8cc0c02f010",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
              "lessThan": "7288c279ddbd654a06c82118c1a3f5570c1807f0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
              "lessThan": "776e85fda752f9a15e0f82dec42ecacd12a9bd94",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
              "lessThan": "1d3e701cda2f41d48aa721b3ebefbe0fbf8d74da",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
              "lessThan": "e981474d7bf1457da12404e169ea147d2c8ecea7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2fdbb8dd01556e1501132b5ad3826e8f71e24a8b",
              "lessThan": "a927f1867e61b78f39f9da0bbba3c98c2ca151fe",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "81775ab858b4236c52c5da7e25cec6e49dd91b46",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b57e150ac2eac791d5d187923b73dc2dafaf67fa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1fdbbe246daf348adaa0739463384b16ceba1fc0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.15.109",
              "lessThan": "5.15.220",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.10.179",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.18.18",
              "lessThan": "5.19",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.19.2",
              "lessThan": "5.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/fuse/file.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.220",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.187",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.156",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.108",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.49",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.13",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.3",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/fuse/file.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:14.507",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1b04d80a27d317064cce2307472f5bef9975bc50",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/1d3e701cda2f41d48aa721b3ebefbe0fbf8d74da",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7288c279ddbd654a06c82118c1a3f5570c1807f0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/776e85fda752f9a15e0f82dec42ecacd12a9bd94",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a61524da59a2f5ac9c8de23ff98b30da769ab144",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a927f1867e61b78f39f9da0bbba3c98c2ca151fe",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dcf30a56624c2a0cfab1bada5b1ca8cc0c02f010",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e981474d7bf1457da12404e169ea147d2c8ecea7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: fix invalidate lock leak on open O_TRUNC DAX failure\n\nfuse_open() takes filemap_invalidate_lock() for a DAX truncate\n(dax_truncate = true) and releases it before the out_inode_unlock\nlabel.  But when fuse_dax_break_layouts() fails, the goto\nout_inode_unlock skips the unlock and leaks the rwsem, so any later\nfault or truncate on the file stalls on the stale lock.\n\nfuse_dax_break_layouts() can fail with -ERESTARTSYS when a signal\ninterrupts the wait for busy DAX pages to drain:\n\n  open(\"file\", O_RDWR | O_TRUNC)\n  └─ fuse_open()\n     ├─ filemap_invalidate_lock()        # dax_truncate\n     └─ fuse_dax_break_layouts()\n        └─ dax_break_layout()\n           └─ wait_page_idle()           # TASK_INTERRUPTIBLE\n              └─ fuse_wait_dax_page()    # unlock, schedule, re-lock\n                 └─ signal → -ERESTARTSYS\n     goto out_inode_unlock               # <- lock leaked\n\nFix this by moving filemap_invalidate_unlock() below the label so\nthat all error paths release the lock, and rename the label to\nout_unlock as it now covers more than just the inode lock."
    }
  ],
  "lastModified": "2026-09-04T16:18:14.507",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}