Executive brief
The Linux kernel's ext4 filesystem has a deadlock vulnerability in the EXT4_IOC_MOVE_EXT ioctl operation. When a user attempts to move file extents between files on different filesystems (such as overlayfs), a circular lock dependency can occur between filesystem freeze operations and inode locks, causing the system to hang and denying service to legitimate operations.
Technical details
The vulnerability is a circular lock dependency (deadlock) in the ext4 ioctl handler for EXT4_IOC_MOVE_EXT. The root cause is that superblock validation (checking that both files belong to the same ext4 filesystem) occurs too late—after inode locks have been acquired via lock_two_nondirectories(). When the donor file resides on a different filesystem (e.g., overlayfs), a concurrent filesystem freeze operation can trigger a deadlock: the freezing thread holds sb_writers write lock, one CPU waits for the freeze to complete while holding an inode lock, and another CPU waits for the inode lock while trying to acquire sb_writers. The fix moves the superblock check before any lock acquisition, ensuring cross-filesystem donor file descriptors are rejected early and preventing the circular dependency. The vulnerability requires local filesystem access (ioctl from userspace) and does not require elevated privileges beyond filesystem interaction.
Affected products
- Linux Linux kernel before fix (approximately 2026-08-15)
Timeline
- 2026-08-15: disclosed