CVE-2026-53049
gfs2: add some missing log locking
Description
In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock, but these functions require exclusion against concurrent transactions. To fix that, add a non-locking __gfs2_log_flush() function. Then, in gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log flushing functions and __gfs2_log_flush().
INFO
Published Date :
June 24, 2026, 5:17 p.m.
Last Modified :
July 21, 2026, 5:23 p.m.
Remotely Exploit :
Yes !
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | CRITICAL | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Take sdp->sd_log_flush_lock before flushing.
- Call __gfs2_log_flush() after taking the lock.
- Review and apply kernel patches for gfs2.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-53049.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-53049 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-53049
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-53049 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-53049 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Jul. 21, 2026
Action Type Old Value New Value Added CWE CWE-667 Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.141 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.91 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.33 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.10 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.175 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.7 up to (excluding) 5.15.209 Added Reference Type kernel.org: https://git.kernel.org/stable/c/3b28eb75afe520972bacc833850c2b30aa0824cd Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/49d9be0722da3a4a893ba905720cba1921834ec3 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/98e8bf249c790d56de1abc4a5f8bd68035a00921 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/bf5fcd9c37c2546beaf7b401d31aefd89017dc3d Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/ca95342cb1b39062a03c115830286f0a426053d5 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/f2f225cf505ac016132ded21690f3ba0a080a4e8 Types: Patch Added Reference Type kernel.org: https://git.kernel.org/stable/c/fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8 Types: Patch -
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 28, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Jun. 24, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': '3b28eb75afe520972bacc833850c2b30aa0824cd', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': 'ca95342cb1b39062a03c115830286f0a426053d5', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': 'bf5fcd9c37c2546beaf7b401d31aefd89017dc3d', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': 'f2f225cf505ac016132ded21690f3ba0a080a4e8', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': '49d9be0722da3a4a893ba905720cba1921834ec3', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': '98e8bf249c790d56de1abc4a5f8bd68035a00921', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': 'fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8', 'versionType': 'git'}], 'programFiles': ['fs/gfs2/log.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.209', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.175', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.141', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.91', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.33', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.10', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/gfs2/log.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock, but these functions require exclusion against concurrent transactions. To fix that, add a non-locking __gfs2_log_flush() function. Then, in gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log flushing functions and __gfs2_log_flush(). Added Reference https://git.kernel.org/stable/c/3b28eb75afe520972bacc833850c2b30aa0824cd Added Reference https://git.kernel.org/stable/c/49d9be0722da3a4a893ba905720cba1921834ec3 Added Reference https://git.kernel.org/stable/c/98e8bf249c790d56de1abc4a5f8bd68035a00921 Added Reference https://git.kernel.org/stable/c/bf5fcd9c37c2546beaf7b401d31aefd89017dc3d Added Reference https://git.kernel.org/stable/c/ca95342cb1b39062a03c115830286f0a426053d5 Added Reference https://git.kernel.org/stable/c/f2f225cf505ac016132ded21690f3ba0a080a4e8 Added Reference https://git.kernel.org/stable/c/fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8