-

CVE-2026-93252

ocfs2: fix circular locking dependency in ocfs2_init_acl()

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: fix circular locking dependency in ocfs2_init_acl()

A lockdep warning indicates a circular locking dependency between
`&oi->ip_xattr_sem` and `&journal->j_trans_barrier`:

WARNING: possible circular locking dependency detected
is trying to acquire lock:
 (&oi->ip_xattr_sem){++++}-{4:4}, at: ocfs2_init_acl+0x2fd/0x7e0
 fs/ocfs2/acl.c:367

but task is already holding lock:
 (&journal->j_trans_barrier){.+.+}-{4:4}, at: ocfs2_start_trans+0x3ab/0x700
 fs/ocfs2/journal.c:369

The deadlock involves two code paths: Path 1 (setxattr) where
`ocfs2_xattr_set()` acquires `ip_xattr_sem` (write) and then starts a
transaction, which acquires `j_trans_barrier` (read); and Path 2
(mkdir/mknod) where `ocfs2_mknod()` starts a transaction (`j_trans_barrier`
read) and then calls `ocfs2_init_acl()`, which attempts to acquire
`ip_xattr_sem` (read) on the parent directory to retrieve the default ACL.

Because rw_semaphores are subject to writer priority, a pending writer on
`j_trans_barrier` (e.g., the journal commit thread) can cause Path 1 to
block, while Path 2 is blocked waiting for Path 1 to release
`ip_xattr_sem`.

The patch fixes the lock ordering by precomputing the ACL state before
starting the OCFS2 transaction, while preserving POSIX ACL storage
semantics and the existing inode/security initialization order. By reading
the parent directory's default ACL and preparing the new inode's ACLs
outside the transaction, `ip_xattr_sem` is always acquired before
`j_trans_barrier`.

`struct ocfs2_acl_state` encapsulates the prepared ACL state, while
`ocfs2_acl_init_prepare()` and `ocfs2_acl_init_release()` avoid code
duplication between `ocfs2_mknod()` and `ocfs2_init_security_and_acl()`.
`ocfs2_calc_xattr_init()` and `ocfs2_init_acl()` use this precomputed
state, removing internal `ip_xattr_sem` acquisition and redundant disk
reads.

Additionally, remove the `ip_xattr_sem` acquisition from
`ocfs2_xattr_set_handle()`. This function is only used while initializing a
new inode that has not yet been inserted into the inode hash or attached to
a dentry, meaning there is no risk of concurrent access and the lock is
unnecessary.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 16c8d569f5704a84164f30ff01b29879f3438065
Version < 4936d4464d1ae10b5fbba64374085a0dcc060560
Status affected
Version 16c8d569f5704a84164f30ff01b29879f3438065
Version < caf3056936fb8b5ce92e419cf8b246ce9c437343
Status affected
Version 16c8d569f5704a84164f30ff01b29879f3438065
Version < 5b7b3c50c39ad0dc27e7418981e01c4183273f89
Status affected
Version 16c8d569f5704a84164f30ff01b29879f3438065
Version < 8d88f52fbbbcc18adf4091a955511d0cf605bf11
Status affected
Version 16c8d569f5704a84164f30ff01b29879f3438065
Version < 8931403ee3dcfe8a24a5267efec9d9460ab7a1b5
Status affected
Version 16c8d569f5704a84164f30ff01b29879f3438065
Version < f8747d81aa6d3efe3ee339a9d912ff3ca6e4d758
Status affected
Version 16c8d569f5704a84164f30ff01b29879f3438065
Version < 1222f7a3183b35c0c566899fdaead5c7c4043076
Status affected
Version 16c8d569f5704a84164f30ff01b29879f3438065
Version < bd7c05fb4a4776dff5a87b19008d28458647d15d
Status affected
Version 15ac59a84750b3afc0a2b6f2636c4f7e6cbd6d5e
Status affected
Version b35bb8a41795caa05e09c3aacf7d78f1f20bac04
Status affected
Version 1d5fdc1307eeb04b334c5dc23e11dbd6068d90eb
Status affected
Version a66174eb4a149b7919d174d9a7ce6ad9909c5ee2
Status affected
Version 3.18.111
Version < 3.19
Status affected
Version 4.4.134
Version < 4.5
Status affected
Version 4.9.104
Version < 4.10
Status affected
Version 4.14.37
Version < 4.15
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.16
Status affected
Version 0
Version < 4.16
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.101
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/4936d4464d1ae10b5fbba64374085a0dcc060560
https://git.kernel.org/stable/c/caf3056936fb8b5ce92e419cf8b246ce9c437343
https://git.kernel.org/stable/c/5b7b3c50c39ad0dc27e7418981e01c4183273f89
https://git.kernel.org/stable/c/8d88f52fbbbcc18adf4091a955511d0cf605bf11
https://git.kernel.org/stable/c/8931403ee3dcfe8a24a5267efec9d9460ab7a1b5
https://git.kernel.org/stable/c/f8747d81aa6d3efe3ee339a9d912ff3ca6e4d758
https://git.kernel.org/stable/c/1222f7a3183b35c0c566899fdaead5c7c4043076
https://git.kernel.org/stable/c/bd7c05fb4a4776dff5a87b19008d28458647d15d