CVE-2026-93268
CVE CVE-2026-93268EUVD EUVD-2026-86140Published 2026-09-24T15:52:07.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ext4: skip extra isize expansion during mount to prevent deadlock ext4_try_to_expand_extra_isize() is called from __ext4_mark_inode_dirty() while holding an active jbd2 handle. During mount (!SB_ACTIVE), the expand path may move xattrs to external blocks and release ea_inodes via iput(). When !SB_ACTIVE, iput() calls write_inode_now() which acquires s_writepages_rwsem, creating a circular lock dependency: s_writepages_rwsem --> jbd2_handle --> xattr_sem --> s_writepages_rwsem This can be triggered via: ext4_process_orphan() -> ext4_truncate() -> ext4_mark_inode_dirty() -> ext4_try_to_expand_extra_isize() or: ext4_evict_inode() -> ext4_mark_inode_dirty() -> ext4_try_to_expand_extra_isize() Skip expansion when !SB_ACTIVE. This is a minor loss of functionality (extra isize won't grow for these inodes during mount), which e2fsck can resolve later if needed.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <7461c60b9c6a839b13ad4c3490681a0cf5aa0637; c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <41897f1bcf4ace5f1f28d0be784b6f4f0e929641; c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <c5e6434cc55f30220b228be237bb666351f9f4dd; patch: 6.1.188; patch: 6.12.110; patch: 5.15.221; c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <2fb8ff81659a57c42bb7b49e8339a2be2a318ef8; patch: 7.3-rc1; c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <1dd4882dbdc8bfdf2182fa388883c143fac0902a; patch: 0; c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <9c3469377b1d8caba6bec6ef3c460810bbfb02cc; patch: 6.18.52; patch: 7.2.6; c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <7ace189b9ea79cf78df9c32b940ce12735f9459a; patch: 6.6.157; 4.7; patch: 5.10.270; c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <7ba09330d9ea6e996228316719eae812d7e04983
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.