Review reviewCritical

CVE-2026-53049

Linux Linux, linux kernel

In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock, but these functions require exclusion against concurrent transactions. To fix that, add a non-locking __gfs2_log_flush() function. Then, in gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log flushing functions and __gfs2_log_flush().

CVSS
9.8
EPSS
0.39%
31.5% percentile
CISA KEV
Not listed
Published
2026.06.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.39%
Technical severityCVSS 9.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock, but these functions require exclusion against concurrent transactions. To fix that, add a non-locking __gfs2_log_flush() function. Then, in gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log flushing functions and __gfs2_log_flush().

Affected product and versions

Product
Linux Linux, linux kernel
Affected versions
>= 5e4c7632aae1cce137792647f4fb6f599d1da893 < 3b28eb75afe520972bacc833850c2b30aa0824cd, >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < ca95342cb1b39062a03c115830286f0a426053d5, >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < bf5fcd9c37c2546beaf7b401d31aefd89017dc3d, >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < f2f225cf505ac016132ded21690f3ba0a080a4e8, >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < 49d9be0722da3a4a893ba905720cba1921834ec3, >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < 98e8bf249c790d56de1abc4a5f8bd68035a00921, >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8, >= 5.7, >= 5.7 < 5.15.209, >= 5.16 < 6.1.175, >= 6.2 < 6.6.141, >= 6.7 < 6.12.91, >= 6.13 < 6.18.33, >= 6.19 < 7.0.10
Fixed versions
5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-667