CVE-2026-80808 PUBLISHED

ext4: stop retrying saturated xattr cache entries

Assigner: Linux
Reserved: 26.08.2026 Published: 04.09.2026 Updated: 04.09.2026

In the Linux kernel, the following vulnerability has been resolved:

ext4: stop retrying saturated xattr cache entries

ext4_xattr_block_set() retries when a cache entry selected for reuse has a saturated reference count after taking the buffer lock. The retry returns to the mbcache lookup without making that entry ineligible, so it can select the same unusable entry indefinitely. A task spinning there can hold the parent directory's i_rwsem and leave concurrent rmdir callers blocked.

Normally a reusable entry has a reference count below EXT4_XATTR_REFCOUNT_MAX because the count and MBE_REUSABLE_B are updated under the same buffer lock. A corrupted filesystem can violate that invariant. The syzbot reproducer reports allocator and xattr corruption before triggering this retry loop.

Check the untrusted on-disk count before incrementing it, avoiding overflow, and clear MBE_REUSABLE_B when it is already saturated. The next lookup then skips the entry that was just proven unusable. This mirrors the normal transition at EXT4_XATTR_REFCOUNT_MAX; the release path marks the entry reusable again on the exact 1024-to-1023 transition.

Using the same QEMU harness and guest parameters, current unpatched Linux hung in 6 of 8 420-second trials with the do_rmdir signature; representative NMI backtraces caught the owner spinning in ext4_xattr_block_set(). The patched kernel completed 28 of 28 trials without a hung-task report; the final twelve trials exercised the reviewed overflow-safe form of the change. syzbot's patch testing also completed without reproducing the hang.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1a56cd972ce121b6cf2517a47a578782bbd2ec95 to 119a2f053242ed75bdd2ebc95baf3ae7db6ccacf (excl.)
  • affected from 1be97463696c7291a3e1547614e96432b0bd3add to 61631352a5b405c89be579de00903b72e6888aa4 (excl.)
  • affected from 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b to 8865cd664484517703df5c18a965dc3227572b87 (excl.)
  • affected from 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b to a40c45268f4358207aa9c53764fed2e05f62986a (excl.)
  • affected from 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b to 889ec86464d261f026f6c334040cfc6c58c99d58 (excl.)
  • affected from 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b to 4902a5cba21aeaf91e6b29e20e0967a5f6abdcd9 (excl.)
  • affected from 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b to 55ee6533c1db7f7656fa8dd19637f3f8b8c08dc5 (excl.)
  • affected from 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b to dbd4aea175ad3c46436acb251e817b4374628072 (excl.)
  • affected from 65f8b80053a1b2fd602daa6814e62d6fa90e5e9b to 54b6bd40898de7906acb2bccc9a96d1b8e6b4323 (excl.)
  • Version 98953044b3cdb2cb7d82e7365b659e2ed4f4ca4d is affected
  • Version af8ecc8d20e72130771cc076bce7fcf17ccda6c4 is affected
  • Version c6fac5cf5a5098732623bcd00a8a3eb9f5465144 is affected
  • Version 96fa141fa295ae9428da73c56c9852053b575c04 is affected
  • affected from 5.10.163 to 5.10.267 (excl.)
  • affected from 5.15.61 to 5.15.218 (excl.)
  • affected from 4.19.270 to 4.20 (excl.)
  • affected from 5.4.229 to 5.5 (excl.)
  • affected from 5.18.18 to 5.19 (excl.)
  • affected from 5.19.2 to 5.20 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.0 is affected
  • unaffected from 0 to 6.0 (excl.)
  • unaffected from 5.10.267 to 5.10.* (incl.)
  • unaffected from 5.15.218 to 5.15.* (incl.)
  • unaffected from 6.1.185 to 6.1.* (incl.)
  • unaffected from 6.6.154 to 6.6.* (incl.)
  • unaffected from 6.12.106 to 6.12.* (incl.)
  • unaffected from 6.18.47 to 6.18.* (incl.)
  • unaffected from 7.1.11 to 7.1.* (incl.)
  • unaffected from 7.2.1 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References