Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-53049: Linux kernel: Data loss from concurrent transactions
CVE-2026-53049
Summary
A bug in the Linux kernel's GFS2 file system could cause data loss when multiple transactions happen at the same time. This has been fixed in a recent update, so it's no longer a concern. If you're using the Linux kernel, make sure you have the latest version installed to stay secure.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| linux | linux_kernel |
>= 5.7, < 5.15.209 >= 5.16, < 6.1.175 >= 6.2, < 6.6.141 >= 6.7, < 6.12.91 >= 6.13, < 6.18.33 >= 6.19, < 7.0.10 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
Original title
In the Linux kernel, the following vulnerability has been resolved:
gfs2: add some missing log locking
Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(),
gfs2_ail1_wait(), a...
Original description
In the Linux kernel, the following vulnerability has been resolved:
gfs2: add some missing log locking
Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(),
gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock,
but these functions require exclusion against concurrent transactions.
To fix that, add a non-locking __gfs2_log_flush() function. Then, in
gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log
flushing functions and __gfs2_log_flush().
gfs2: add some missing log locking
Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(),
gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock,
but these functions require exclusion against concurrent transactions.
To fix that, add a non-locking __gfs2_log_flush() function. Then, in
gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log
flushing functions and __gfs2_log_flush().
nvd CVSS3.1
9.8
Vulnerability type
CWE-667
Improper Locking
- https://git.kernel.org/stable/c/3b28eb75afe520972bacc833850c2b30aa0824cd
- https://git.kernel.org/stable/c/49d9be0722da3a4a893ba905720cba1921834ec3
- https://git.kernel.org/stable/c/98e8bf249c790d56de1abc4a5f8bd68035a00921
- https://git.kernel.org/stable/c/bf5fcd9c37c2546beaf7b401d31aefd89017dc3d
- https://git.kernel.org/stable/c/ca95342cb1b39062a03c115830286f0a426053d5
- https://git.kernel.org/stable/c/f2f225cf505ac016132ded21690f3ba0a080a4e8
- https://git.kernel.org/stable/c/fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8
Published: 24 Jun 2026 · Updated: 23 Jul 2026 · First seen: 28 Jun 2026