{"id":"CVE-2026-93269","published":"2026-09-24T16:17:23.873","lastModified":"2026-09-24T16:17:23.873","description":"In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix circular lock dependency in ext4_ext_migrate\n\nMove iput(tmp_inode) after ext4_writepages_up_write() to avoid a\ncircular lock dependency between s_writepages_rwsem and sb_internal\n(freeze protection).\n\nThe deadlock scenario:\n\n  CPU0 (EXT4_IOC_MIGRATE)        CPU1 (orphan cleanup during mount)\n  ----                           ----\n  ext4_ext_migrate()\n    ext4_writepages_down_write()\n      s_writepages_rwsem (write)\n                                 ext4_evict_inode()\n                                   sb_start_intwrite()   [sb_internal]\n                                   ...\n                                     ext4_writepages()\n                                       s_writepages_rwsem (read) [BLOCKED]\n    iput(tmp_inode)\n      ext4_evict_inode()\n        sb_start_intwrite()         [BLOCKED]\n\nThe tmp_inode is a temporary inode with nlink=0 created solely for\nbuilding the extent tree.  Its eviction does not require\ns_writepages_rwsem protection, so deferring iput() until after\nreleasing the rwsem is safe.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/32f7ab52875ec7f800ca67e7176e5743a84baddf","tags":[]},{"url":"https://git.kernel.org/stable/c/452950461241dfed8b1d32e94b227db38c99c5af","tags":[]},{"url":"https://git.kernel.org/stable/c/a897682793eba5de51ee6f3152760374afa629cf","tags":[]},{"url":"https://git.kernel.org/stable/c/ada23457d4748d6e9c36c6f871fc29a6f558c48c","tags":[]},{"url":"https://git.kernel.org/stable/c/e4223231b6860141813637a6413c2371ae4d6fa8","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}