PT-2026-85649 · Linux · Linux

CVE-2026-80808

·

Publicado

2026-09-04

·

Atualizado

2026-09-04

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
ext4: stop retrying saturated xattr cache entries
ext4 xattr block set() retries when a cache entry selected for reuse has a saturated reference count after taking the buffer lock. The retry returns to the mbcache lookup without making that entry ineligible, so it can select the same unusable entry indefinitely. A task spinning there can hold the parent directory's i rwsem and leave concurrent rmdir callers blocked.
Normally a reusable entry has a reference count below EXT4 XATTR REFCOUNT MAX because the count and MBE REUSABLE B are updated under the same buffer lock. A corrupted filesystem can violate that invariant. The syzbot reproducer reports allocator and xattr corruption before triggering this retry loop.
Check the untrusted on-disk count before incrementing it, avoiding overflow, and clear MBE REUSABLE B when it is already saturated. The next lookup then skips the entry that was just proven unusable. This mirrors the normal transition at EXT4 XATTR REFCOUNT MAX; the release path marks the entry reusable again on the exact 1024-to-1023 transition.
Using the same QEMU harness and guest parameters, current unpatched Linux hung in 6 of 8 420-second trials with the do rmdir signature; representative NMI backtraces caught the owner spinning in ext4 xattr block set(). The patched kernel completed 28 of 28 trials without a hung-task report; the final twelve trials exercised the reviewed overflow-safe form of the change. syzbot's patch testing also completed without reproducing the hang.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-80808

Produtos afetados

Linux