Junglewise Threat Intelligence

CVE-2026-92503: Linux kernel ext4 ABBA deadlock in xattr inode cache lookup

CVE-2026-92503 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A deadlock condition was discovered in the Linux kernel's ext4 filesystem when using the ea_inode mount option for extended attributes. The vulnerability can cause system processes to hang when multiple threads access extended attributes concurrently, potentially leading to service unavailability. This has been addressed with a non-blocking inode cache lookup mechanism.

Technical details

This is an ABBA deadlock vulnerability in ext4's extended attributes (xattr) handling, occurring in the ext4_xattr_inode_cache_find() function when the ea_inode mount option is enabled. The deadlock arises from circular lock dependencies: one thread holds an mbcache_entry reference while waiting for inode eviction to complete via __wait_on_freeing_inode(), while the eviction thread waits for that same mbcache_entry reference to be released via mb_cache_entry_wait_unused(). The fix introduces an EXT4_IGET_NOWAIT flag that uses find_inode_nowait() to perform non-blocking inode cache lookups, returning -ENOENT immediately on cache miss or if the inode is in a state transition (I_FREEING, I_WILL_FREE, I_CREATING) rather than blocking. The patch includes proper handling of newly-created inodes and validation of returned inodes to maintain VFS-layer safety.

Affected products

  • Linux Linux kernel affected versions not specified in advisory

Timeline

  • 2026-09-17: disclosed

Related threats