CVE-2026-93252None▾ SunlitIn the Linux kernel, the following vulnerability has been resolved: ocfs2: fix circular locking dependency in ocfs2_init_acl() A lockdep warning indicates a circular locking dependency between `&oi->ip_xattr_sem` and `&journal->j_trans…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: fix circular locking dependency in ocfs2_init_acl()
A lockdep warning indicates a circular locking dependency between
&oi->ip_xattr_sem and &journal->j_trans_barrier:
WARNING: possible circular locking dependency detected is trying to acquire lock: (&oi->ip_xattr_sem){++++}-{4:4}, at: ocfs2_init_acl+0x2fd/0x7e0 fs/ocfs2/acl.c:367
but task is already holding lock: (&journal->j_trans_barrier){.+.+}-{4:4}, at: ocfs2_start_trans+0x3ab/0x700 fs/ocfs2/journal.c:369
The deadlock involves two code paths: Path 1 (setxattr) where
ocfs2_xattr_set() acquires ip_xattr_sem (write) and then starts a
transaction, which acquires j_trans_barrier (read); and Path 2
(mkdir/mknod) where ocfs2_mknod() starts a transaction (j_trans_barrier
read) and then calls ocfs2_init_acl(), which attempts to acquire
ip_xattr_sem (read) on the parent directory to retrieve the default ACL.
Because rw_semaphores are subject to writer priority, a pending writer on
j_trans_barrier (e.g., the journal commit thread) can cause Path 1 to
block, while Path 2 is blocked waiting for Path 1 to release
ip_xattr_sem.
The patch fixes the lock ordering by precomputing the ACL state before
starting the OCFS2 transaction, while preserving POSIX ACL storage
semantics and the existing inode/security initialization order. By reading
the parent directory's default ACL and preparing the new inode's ACLs
outside the transaction, ip_xattr_sem is always acquired before
j_trans_barrier.
struct ocfs2_acl_state encapsulates the prepared ACL state, while
ocfs2_acl_init_prepare() and ocfs2_acl_init_release() avoid code
duplication between ocfs2_mknod() and ocfs2_init_security_and_acl().
ocfs2_calc_xattr_init() and ocfs2_init_acl() use this precomputed
state, removing internal ip_xattr_sem acquisition and redundant disk
reads.
Additionally, remove the ip_xattr_sem acquisition from
ocfs2_xattr_set_handle(). This function is only used while initializing a
new inode that has not yet been inserted into the inode hash or attached to
a dentry, meaning there is no risk of concurrent access and the lock is
unnecessary.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-97409NoneIn the Linux kernel, the following vulnerability has been resolved: nvme-fc: Do not cancel requests in io target before it is initialized A new nvme-fc controller in CONNECTING state sees admin request timeout schedules ctrl->ioerr_wor…
CVE-2026-97408NoneIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: validate connectionless PSM length Connectionless L2CAP frames carry a two-byte PSM at the start of the payload
CVE-2026-97407NoneIn the Linux kernel, the following vulnerability has been resolved: ASoC: rockchip: rockchip_pdm: Handle runtime PM resume failures in set_fmt rockchip_pdm_set_fmt() calls pm_runtime_get_sync() before accessing hardware registers, but …
CVE-2026-97413NoneIn the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs-srv: Fix integer underflow in process_read and process_write usr_len is read from a network-supplied message field (le16_to_cpu) and used to compute data_len…
CVE-2026-97412NoneIn the Linux kernel, the following vulnerability has been resolved: pds_core: quiesce DMA before freeing resources pdsc_teardown() frees DMA buffers but does not disable bus mastering, leaving the device able to perform DMA after the b…
CVE-2026-97411NoneIn the Linux kernel, the following vulnerability has been resolved: net: ibm: emac: mal: fix potential system hang in mal_remove() napi_disable() is not idempotent and calling it on an already-disabled or unenabled NAPI context will ca…