Junglewise Threat Intelligence

CVE-2026-45895: Linux Kernel livelock in quota subsystem during filesystem freeze

CVE-2026-45895 · Severity: info · CVSS 4 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's disk quota management system can cause a system hang or 'livelock.' When a system administrator attempts to freeze a filesystem (a common step during backups) while quota operations are active, the system may become unresponsive and experience 100% CPU usage. This can lead to a complete denial of service for the affected server, requiring a hard reboot to recover.

Technical details

A livelock exists in the Linux kernel's quota subsystem between quotactl and freeze_super. When a filesystem is frozen, quotactl_block() enters a retry loop waiting for a thaw. In kernels with preemption disabled, this loop lacks scheduling points, preventing the CPU from reaching an RCU quiescent state. This blocks synchronize_rcu() in the freezer thread, which in turn prevents the freezer from advancing, while the quota process spins indefinitely. The fix involves adding cond_resched() to the retry loop to allow RCU synchronization to complete. The issue is most prominent on single-core systems or when both processes are pinned to the same CPU.

Affected products

  • Linux Linux Kernel All versions prior to the fix in 2026

Timeline

  • 2026-01-15: patched: Initial fix authored by Google engineers
  • 2026-05-27: advisory: CVE-2026-45895 published in NVD and kernel.org stable trees

References