PT-2026-85649 · Linux · Linux

CVE-2026-80808

·

Published

2026-09-04

·

Updated

2026-09-04

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ext4: stop retrying saturated xattr cache entries
ext4 xattr block set() retries when a cache entry selected for reuse has a saturated reference count after taking the buffer lock. The retry returns to the mbcache lookup without making that entry ineligible, so it can select the same unusable entry indefinitely. A task spinning there can hold the parent directory's i rwsem and leave concurrent rmdir callers blocked.
Normally a reusable entry has a reference count below EXT4 XATTR REFCOUNT MAX because the count and MBE REUSABLE B are updated under the same buffer lock. A corrupted filesystem can violate that invariant. The syzbot reproducer reports allocator and xattr corruption before triggering this retry loop.
Check the untrusted on-disk count before incrementing it, avoiding overflow, and clear MBE REUSABLE B when it is already saturated. The next lookup then skips the entry that was just proven unusable. This mirrors the normal transition at EXT4 XATTR REFCOUNT MAX; the release path marks the entry reusable again on the exact 1024-to-1023 transition.
Using the same QEMU harness and guest parameters, current unpatched Linux hung in 6 of 8 420-second trials with the do rmdir signature; representative NMI backtraces caught the owner spinning in ext4 xattr block set(). The patched kernel completed 28 of 28 trials without a hung-task report; the final twelve trials exercised the reviewed overflow-safe form of the change. syzbot's patch testing also completed without reproducing the hang.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80808

Affected Products

Linux