-

CVE-2026-89491

ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()

Patch series "ocfs2: cluster: o2hb_region_pin() fixes", v2.

This series fixes three related issues in o2hb_region_pin(), all are from
the original implementation in commit: 58a3158a5d17 ("ocfs2/cluster:
Pin/unpin o2hb regions"):

1) It is called with o2hb_live_lock (a spinlock) held, but the
   underlying configfs_depend_item() sleeps (takes inode rwsem and
   pins the filesystem).  This triggers BUG under
   CONFIG_DEBUG_ATOMIC_SLEEP.

2) When called from the configfs drop_item callback, it creates a
   lock order inversion: parent inode_lock -> configfs root
   inode_lock, which can deadlock against subsystem unregistration
   paths taking root -> parent.

3) If pinning fails partway through o2hb_region_inc_user(), the
   o2hb_dependent_users counter is leaked and partially-pinned
   regions are never released, leaving heartbeat regions
   unprotected on subsequent mounts.

Patch 1 reworks o2hb_region_pin() to drop o2hb_live_lock across each
sleeping configfs_depend_item() call, using a config_item reference to
keep the region alive while unlocked.

Patch 2 adds a from_callback parameter to select
configfs_depend_item_unlocked() when called from configfs context,
avoiding the inode_lock nesting.

Patch 3 fixes the error path in o2hb_region_inc_user() to unpin and
decrement the counter on failure.


This patch (of 3):

o2hb_region_pin() is always called with the o2hb_live_lock spinlock held
(from o2hb_region_inc_user() and o2hb_heartbeat_group_drop_item()), but it
calls o2nm_depend_item() -> configfs_depend_item(), which sleeps: it pins
the configfs filesystem and takes the configfs root inode rwsem.  Under
CONFIG_DEBUG_ATOMIC_SLEEP this triggers:

  BUG: sleeping function called from invalid context at kernel/locking/rwsem.c
  in_atomic(): 1, ... name: mount.ocfs2
    down_write
    configfs_depend_item
    o2hb_region_pin
    o2hb_region_inc_user
    o2hb_register_callback
    dlm_register_domain_handlers
    ...
    ocfs2_dlm_init
    ocfs2_mount_volume
    ocfs2_fill_super

Rework o2hb_region_pin() to pin one region at a time with the lock dropped
across the sleeping call: under o2hb_live_lock find the next eligible
region and take a config_item reference to keep it alive, drop the lock,
call o2nm_depend_item(), then retake the lock and record the pin.  The
config_item_put() is done with the lock released as well, since
o2hb_region_release() also acquires o2hb_live_lock and can sleep.  The
region list may change while unlocked, so the scan restarts from the top
after each pin.  Local heartbeat still pins only the matching region;
global heartbeat pins all eligible regions.

The unpin path is unaffected: configfs_undepend_item() only takes a
spinlock and does not sleep.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e
Version < 4d64f8da82fb9e8dbd5aa9b64c9bb6ac0decea03
Status affected
Version 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e
Version < 3b790774280a610f8bdbd5d4260a07345bcf8e04
Status affected
Version 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e
Version < 0cbc2f20a6ea7b4a59efa9171b7c694cdd196507
Status affected
Version 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e
Version < c9be4de77f97f383b750698e1517fd296041f4bb
Status affected
Version 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e
Version < 49002acc520c61002ad195894ac391c94317d3ba
Status affected
Version 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e
Version < ce035f208d68b812d83e5482980f2b1c88a9cd94
Status affected
Version 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e
Version < 470212a5eefabcc16b8e2f7fe2844b8737fe571c
Status affected
Version 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e
Version < af09df89db9a68a1d76df0f75667998135bc8d65
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.38
Status affected
Version 0
Version < 2.6.38
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/49002acc520c61002ad195894ac391c94317d3ba
https://git.kernel.org/stable/c/ce035f208d68b812d83e5482980f2b1c88a9cd94
https://git.kernel.org/stable/c/470212a5eefabcc16b8e2f7fe2844b8737fe571c
https://git.kernel.org/stable/c/af09df89db9a68a1d76df0f75667998135bc8d65
https://git.kernel.org/stable/c/0cbc2f20a6ea7b4a59efa9171b7c694cdd196507
https://git.kernel.org/stable/c/3b790774280a610f8bdbd5d4260a07345bcf8e04
https://git.kernel.org/stable/c/4d64f8da82fb9e8dbd5aa9b64c9bb6ac0decea03
https://git.kernel.org/stable/c/c9be4de77f97f383b750698e1517fd296041f4bb