Junglewise Threat Intelligence

CVE-2026-31598: Linux Kernel OCFS2 deadlock in unlink and dio_end_io_write

CVE-2026-31598 · Severity: high · CVSS 7.5 · Published 2026-04-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A flaw was found in the OCFS2 file system component of the Linux kernel. This vulnerability can cause a system deadlock, leading to a complete loss of availability for the affected server. In a business environment, this could result in unexpected service outages and disruption of operations that rely on shared storage.

Technical details

A deadlock vulnerability exists in the OCFS2 file system of the Linux kernel due to an ABBA lock ordering violation. Specifically, 'ocfs2_unlink' acquires the orphan directory 'inode_lock' before 'ip_alloc_sem', while 'ocfs2_dio_end_io_write' acquires them in the reverse order. This circular dependency can be triggered during concurrent file unlinking and direct I/O write operations. An attacker or a specific sequence of system events can cause the kernel threads to hang indefinitely. The fix involves moving the 'ocfs2_del_inode_from_orphan' call outside of the 'ip_alloc_sem' lock scope in the direct I/O path. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 4.6 to 6.6.136, 6.7 to 6.12.83, 6.13 to 6.18.24, 6.19 to 6.19.14, 7.0 to 7.0.1

Timeline

  • 2026-04-24: disclosed
  • 2026-04-24: advisory
  • 2026-04-22: patched: Patch committed to stable tree

References

Related threats