All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-89491: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()
@ 2026-09-11 19:43 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:43 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()

Patch series "ocfs2: cluster: o2hb_region_pin() fixes", v2.

This series fixes three related issues in o2hb_region_pin(), all are from
the original implementation in commit: 58a3158a5d17 ("ocfs2/cluster:
Pin/unpin o2hb regions"):

1) It is called with o2hb_live_lock (a spinlock) held, but the
   underlying configfs_depend_item() sleeps (takes inode rwsem and
   pins the filesystem).  This triggers BUG under
   CONFIG_DEBUG_ATOMIC_SLEEP.

2) When called from the configfs drop_item callback, it creates a
   lock order inversion: parent inode_lock -> configfs root
   inode_lock, which can deadlock against subsystem unregistration
   paths taking root -> parent.

3) If pinning fails partway through o2hb_region_inc_user(), the
   o2hb_dependent_users counter is leaked and partially-pinned
   regions are never released, leaving heartbeat regions
   unprotected on subsequent mounts.

Patch 1 reworks o2hb_region_pin() to drop o2hb_live_lock across each
sleeping configfs_depend_item() call, using a config_item reference to
keep the region alive while unlocked.

Patch 2 adds a from_callback parameter to select
configfs_depend_item_unlocked() when called from configfs context,
avoiding the inode_lock nesting.

Patch 3 fixes the error path in o2hb_region_inc_user() to unpin and
decrement the counter on failure.


This patch (of 3):

o2hb_region_pin() is always called with the o2hb_live_lock spinlock held
(from o2hb_region_inc_user() and o2hb_heartbeat_group_drop_item()), but it
calls o2nm_depend_item() -> configfs_depend_item(), which sleeps: it pins
the configfs filesystem and takes the configfs root inode rwsem.  Under
CONFIG_DEBUG_ATOMIC_SLEEP this triggers:

  BUG: sleeping function called from invalid context at kernel/locking/rwsem.c
  in_atomic(): 1, ... name: mount.ocfs2
    down_write
    configfs_depend_item
    o2hb_region_pin
    o2hb_region_inc_user
    o2hb_register_callback
    dlm_register_domain_handlers
    ...
    ocfs2_dlm_init
    ocfs2_mount_volume
    ocfs2_fill_super

Rework o2hb_region_pin() to pin one region at a time with the lock dropped
across the sleeping call: under o2hb_live_lock find the next eligible
region and take a config_item reference to keep it alive, drop the lock,
call o2nm_depend_item(), then retake the lock and record the pin.  The
config_item_put() is done with the lock released as well, since
o2hb_region_release() also acquires o2hb_live_lock and can sleep.  The
region list may change while unlocked, so the scan restarts from the top
after each pin.  Local heartbeat still pins only the matching region;
global heartbeat pins all eligible regions.

The unpin path is unaffected: configfs_undepend_item() only takes a
spinlock and does not sleep.

The Linux kernel CVE team has assigned CVE-2026-89491 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 2.6.38 with commit 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e and fixed in 6.12.109 with commit 49002acc520c61002ad195894ac391c94317d3ba
	Issue introduced in 2.6.38 with commit 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e and fixed in 6.18.50 with commit ce035f208d68b812d83e5482980f2b1c88a9cd94
	Issue introduced in 2.6.38 with commit 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e and fixed in 7.2.4 with commit 470212a5eefabcc16b8e2f7fe2844b8737fe571c
	Issue introduced in 2.6.38 with commit 58a3158a5d17ddf4894db9e8ccaf92093ff8e42e and fixed in 7.3-rc1 with commit af09df89db9a68a1d76df0f75667998135bc8d65

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-89491
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/ocfs2/cluster/heartbeat.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/49002acc520c61002ad195894ac391c94317d3ba
	https://git.kernel.org/stable/c/ce035f208d68b812d83e5482980f2b1c88a9cd94
	https://git.kernel.org/stable/c/470212a5eefabcc16b8e2f7fe2844b8737fe571c
	https://git.kernel.org/stable/c/af09df89db9a68a1d76df0f75667998135bc8d65

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-11 19:52 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:43 CVE-2026-89491: ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin() Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.