Executive brief
The Linux kernel's NTFS filesystem implementation contains a deadlock vulnerability in the rename operation. When file rename, sync, and inode write operations compete for file metadata locks, the system can deadlock, causing processes to hang and making the system unresponsive. This impacts systems using NTFS volumes on Linux.
Technical details
A deadlock condition (ABBA deadlock) exists in the NTFS subsystem's rename operation (ntfs_rename) when it conflicts with fsync and write-back operations. The vulnerability occurs because ntfs_rename() acquires mutex locks in an order (old inode → old directory → new inode/directory) that conflicts with the lock order used by ntfs_file_fsync(), ntfs_dir_fsync(), and __ntfs_write_inode() (child inode → parent directory). The fix reorders the lock acquisition in ntfs_rename() to match the child-to-parent order, preventing the deadlock cycle. This is a kernel-level bug that requires no special privileges or network access to trigger—any local process renaming files on an NTFS mount can induce the condition under concurrent I/O load.
Affected products
- Linux Linux kernel Applies to all kernel versions; patch made available 2026-06-30
Timeline
- 2026-06-30: disclosed: Vulnerability reported and patch submitted
- 2026-07-24: patched: Patch integrated into stable kernel series