Executive brief
A flaw was found in the OCFS2 file system component of the Linux kernel. This vulnerability can cause a system deadlock, leading to a complete loss of availability for the affected server. In a business environment, this could result in unexpected service outages and disruption of operations that rely on shared storage.
Technical details
A deadlock vulnerability exists in the OCFS2 file system of the Linux kernel due to an ABBA lock ordering violation. Specifically, 'ocfs2_unlink' acquires the orphan directory 'inode_lock' before 'ip_alloc_sem', while 'ocfs2_dio_end_io_write' acquires them in the reverse order. This circular dependency can be triggered during concurrent file unlinking and direct I/O write operations. An attacker or a specific sequence of system events can cause the kernel threads to hang indefinitely. The fix involves moving the 'ocfs2_del_inode_from_orphan' call outside of the 'ip_alloc_sem' lock scope in the direct I/O path. Patches have been released for multiple stable kernel branches.
Affected products
- Linux Linux Kernel 4.6 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1
Timeline
- 2026-04-24: disclosed
- 2026-04-24: advisory
- 2026-04-22: patched: Patch committed to stable tree
References
- https://git.kernel.org/stable/c/297d8d7bb6a2bf133d3a3636edbdf94101cbd719
- https://git.kernel.org/stable/c/2b884d52273c60c298bd570163e8053657bbaff6
- https://git.kernel.org/stable/c/32630dee18c6bb2175c8a865a474749492eaf19c
- https://git.kernel.org/stable/c/4b80b5a838a32437f2cae0662578bac216a2c51a
- https://git.kernel.org/stable/c/93f35419eb84d58820040642cb6e7528fe4aba7a
- https://git.kernel.org/stable/c/b02da26a992db0c0e2559acbda0fc48d4a2fd337
- https://git.kernel.org/stable/c/bc0fb5c7d54c78be43a536df0e20dee32adb27d3