From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 984A4582B98 for ; Fri, 11 Sep 2026 19:52:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156368; cv=none; b=DRaEK53Tqsaqvx9l6Nz9KXIh8KAzvLdxkxEAmVuLsi0dY8wPZDlz+mta70cgMHbjqhelmsmG+hAL73aSqGU+xABj4tghernCJVr7ML//Kha262dwxrNVRFEKXiYiprs+sqaRVJjBIySBTgodXzO0cfAm7aFlTGotElr0kq8WI3w= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156368; c=relaxed/simple; bh=AZ1B31kJXO8/uqtFPVT3gleeoosTy9NbSeAglWi/rAk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=MbobMztPpI1dfpInLEhRw17CfqnyvEoq/L8NxgwN1B25FrzMNURDTuxSgnj1cVmOzONAotHysfyjMu359TWihBsznFxvkKWmVlJE9xaqs8BvKIjS3+0bP7Tu12EjMz9c2nW2D5jQb+PWpL7Wn0Z9z/AdtSg90AxMF3G+l5Wk26I= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=inPnplbS; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="inPnplbS" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 0BD611F00898; Fri, 11 Sep 2026 19:52:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156357; bh=HD0TK280CIoR84GbxVvEDdCHVHeqJrUEiehvOaSlI7Y=; h=From:To:Cc:Subject:Date:Reply-To; b=inPnplbShQxGimVvNwUD/zi0IBEPmVXIsSmoCtUjcSa0v0NZMSk1PgkKwe4ZdQNzE nYm5jq9Fb5chVOjeHAa6qWdfLd3qxwd1C/WCZ9O9Ilgzo+pnqjG39WLhVhWpHXkeG2 s9r6MlwjIc/YASIYuxPIxGtB0ThaSDTWJ9cAPl9o= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89491: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() Date: Fri, 11 Sep 2026 21:43:00 +0200 Message-ID: <2026091107-CVE-2026-89491-eea0@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=5046; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=rcWvmyIdTyzCNVo8sP5KUTUDWXvkEpfDok+jxS1zaoc=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIkP2yR7dFKsV9VXF8oft7MlNs2Ycnr3gZsGaqqV3o lM8Px1v74hlYRBkYpAVU2T5so3n6P6KQ4pehranYeawMoEMYeDiFICJGOYzLDh0xKp75x+LqueX vjVpHbK+Y9mstYphwbEC5pSphtvnxlx27Toz+XLO1+dJXAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() Patch series "ocfs2: cluster: o2hb_region_pin() fixes", v2. This series fixes three related issues in o2hb_region_pin(), all are from the original implementation in commit: 58a3158a5d17 ("ocfs2/cluster: Pin/unpin o2hb regions"): 1) It is called with o2hb_live_lock (a spinlock) held, but the underlying configfs_depend_item() sleeps (takes inode rwsem and pins the filesystem). This triggers BUG under CONFIG_DEBUG_ATOMIC_SLEEP. 2) When called from the configfs drop_item callback, it creates a lock order inversion: parent inode_lock -> configfs root inode_lock, which can deadlock against subsystem unregistration paths taking root -> parent. 3) If pinning fails partway through o2hb_region_inc_user(), the o2hb_dependent_users counter is leaked and partially-pinned regions are never released, leaving heartbeat regions unprotected on subsequent mounts. Patch 1 reworks o2hb_region_pin() to drop o2hb_live_lock across each sleeping configfs_depend_item() call, using a config_item reference to keep the region alive while unlocked. Patch 2 adds a from_callback parameter to select configfs_depend_item_unlocked() when called from configfs context, avoiding the inode_lock nesting. Patch 3 fixes the error path in o2hb_region_inc_user() to unpin and decrement the counter on failure. This patch (of 3): o2hb_region_pin() is always called with the o2hb_live_lock spinlock held (from o2hb_region_inc_user() and o2hb_heartbeat_group_drop_item()), but it calls o2nm_depend_item() -> configfs_depend_item(), which sleeps: it pins the configfs filesystem and takes the configfs root inode rwsem. Under CONFIG_DEBUG_ATOMIC_SLEEP this triggers: BUG: sleeping function called from invalid context at kernel/locking/rwsem.c in_atomic(): 1, ... name: mount.ocfs2 down_write configfs_depend_item o2hb_region_pin o2hb_region_inc_user o2hb_register_callback dlm_register_domain_handlers ... ocfs2_dlm_init ocfs2_mount_volume ocfs2_fill_super Rework o2hb_region_pin() to pin one region at a time with the lock dropped across the sleeping call: under o2hb_live_lock find the next eligible region and take a config_item reference to keep it alive, drop the lock, call o2nm_depend_item(), then retake the lock and record the pin. The config_item_put() is done with the lock released as well, since o2hb_region_release() also acquires o2hb_live_lock and can sleep. The region list may change while unlocked, so the scan restarts from the top after each pin. Local heartbeat still pins only the matching region; global heartbeat pins all eligible regions. The unpin path is unaffected: configfs_undepend_item() only takes a spinlock and does not sleep. The Linux kernel CVE team has assigned CVE-2026-89491 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.38 with commit 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e and fixed in 6.12.109 with commit 49002acc520c61002ad195894ac391c94317d3ba Issue introduced in 2.6.38 with commit 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e and fixed in 6.18.50 with commit ce035f208d68b812d83e5482980f2b1c88a9cd94 Issue introduced in 2.6.38 with commit 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e and fixed in 7.2.4 with commit 470212a5eefabcc16b8e2f7fe2844b8737fe571c Issue introduced in 2.6.38 with commit 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e and fixed in 7.3-rc1 with commit af09df89db9a68a1d76df0f75667998135bc8d65 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89491 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/ocfs2/cluster/heartbeat.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/49002acc520c61002ad195894ac391c94317d3ba https://git.kernel.org/stable/c/ce035f208d68b812d83e5482980f2b1c88a9cd94 https://git.kernel.org/stable/c/470212a5eefabcc16b8e2f7fe2844b8737fe571c https://git.kernel.org/stable/c/af09df89db9a68a1d76df0f75667998135bc8d65