9.8
CRITICAL CVSS 3.1
CVE-2026-53049
gfs2: add some missing log locking
Description

In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock, but these functions require exclusion against concurrent transactions. To fix that, add a non-locking __gfs2_log_flush() function. Then, in gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log flushing functions and __gfs2_log_flush().

INFO

Published Date :

June 24, 2026, 5:17 p.m.

Last Modified :

July 21, 2026, 5:23 p.m.

Remotely Exploit :

Yes !

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-53049 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 CRITICAL 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Solution
Add log locking to gfs2_logd to prevent race conditions.
  • Take sdp->sd_log_flush_lock before flushing.
  • Call __gfs2_log_flush() after taking the lock.
  • Review and apply kernel patches for gfs2.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-53049 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-53049 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-53049 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-53049 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Jul. 21, 2026

    Action Type Old Value New Value
    Added CWE CWE-667
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.141 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.91 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.33 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.10 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.175 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.7 up to (excluding) 5.15.209
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/3b28eb75afe520972bacc833850c2b30aa0824cd Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/49d9be0722da3a4a893ba905720cba1921834ec3 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/98e8bf249c790d56de1abc4a5f8bd68035a00921 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/bf5fcd9c37c2546beaf7b401d31aefd89017dc3d Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/ca95342cb1b39062a03c115830286f0a426053d5 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/f2f225cf505ac016132ded21690f3ba0a080a4e8 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8 Types: Patch
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 28, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 24, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': '3b28eb75afe520972bacc833850c2b30aa0824cd', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': 'ca95342cb1b39062a03c115830286f0a426053d5', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': 'bf5fcd9c37c2546beaf7b401d31aefd89017dc3d', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': 'f2f225cf505ac016132ded21690f3ba0a080a4e8', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': '49d9be0722da3a4a893ba905720cba1921834ec3', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': '98e8bf249c790d56de1abc4a5f8bd68035a00921', 'versionType': 'git'}, {'status': 'affected', 'version': '5e4c7632aae1cce137792647f4fb6f599d1da893', 'lessThan': 'fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8', 'versionType': 'git'}], 'programFiles': ['fs/gfs2/log.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.7'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.7', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.15.209', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.175', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.141', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.91', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.33', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.10', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/gfs2/log.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock, but these functions require exclusion against concurrent transactions. To fix that, add a non-locking __gfs2_log_flush() function. Then, in gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log flushing functions and __gfs2_log_flush().
    Added Reference https://git.kernel.org/stable/c/3b28eb75afe520972bacc833850c2b30aa0824cd
    Added Reference https://git.kernel.org/stable/c/49d9be0722da3a4a893ba905720cba1921834ec3
    Added Reference https://git.kernel.org/stable/c/98e8bf249c790d56de1abc4a5f8bd68035a00921
    Added Reference https://git.kernel.org/stable/c/bf5fcd9c37c2546beaf7b401d31aefd89017dc3d
    Added Reference https://git.kernel.org/stable/c/ca95342cb1b39062a03c115830286f0a426053d5
    Added Reference https://git.kernel.org/stable/c/f2f225cf505ac016132ded21690f3ba0a080a4e8
    Added Reference https://git.kernel.org/stable/c/fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.