Answer in brief
CVE-2026-93268 records a Unknown severity vulnerability in ext4: skip extra isize expansion during mount to prevent deadlock. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <41897f1bcf4ace5f1f28d0be784b6f4f0e929641 || >=c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <9c3469377b1d8caba6bec6ef3c460810bbfb02cc || >=c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <1dd4882dbdc8bfdf2182fa388883c143fac0902a || >=c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <7ba09330d9ea6e996228316719eae812d7e04983 || >=c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <c5e6434cc55f30220b228be237bb666351f9f4dd || >=c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <7ace189b9ea79cf78df9c32b940ce12735f9459a || >=c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <2fb8ff81659a57c42bb7b49e8339a2be2a318ef8 || >=c8585c6fcaf2011de54c3592e80a634a2b9e1a7f <7461c60b9c6a839b13ad4c3490681a0cf5aa0637 | 41897f1bcf4ace5f1f28d0be784b6f4f0e929641, 9c3469377b1d8caba6bec6ef3c460810bbfb02cc, 1dd4882dbdc8bfdf2182fa388883c143fac0902a, 7ba09330d9ea6e996228316719eae812d7e04983, c5e6434cc55f30220b228be237bb666351f9f4dd, 7ace189b9ea79cf78df9c32b940ce12735f9459a, 2fb8ff81659a57c42bb7b49e8339a2be2a318ef8, 7461c60b9c6a839b13ad4c3490681a0cf5aa0637 |
| Linux/Linuxgeneric | 4.7 | Not reported |
Published upstream
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 24, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 25, 2026
In the Linux kernel, the following vulnerability has been resolved: ext4: skip extra isize expansion during mount to prevent deadlock ext4_try_to_expand_extra_isize() is called from __ext4_mark_inode_dirty() while holding an active jbd2 handle. During mount (!SB_ACTIVE), the expand path may move xattrs to external blocks and release ea_inodes via iput(). When !SB_ACTIVE, iput() calls write_inode_now() which acquires s_writepages_rwsem, creating a circular lock dependency: s_writepages_rwsem --> jbd2_handle --> xattr_sem --> s_writepages_rwsem This can be triggered via: ext4_process_orphan() -> ext4_truncate() -> ext4_mark_inode_dirty() -> ext4_try_to_expand_extra_isize() or: ext4_evict_inode() -> ext4_mark_inode_dirty() -> ext4_try_to_expand_extra_isize() Skip expansion when !SB_ACTIVE. This is a minor loss of functionality (extra isize won't grow for these inodes during mount), which e2fsck can resolve later if needed.
Quoted source text, attributed separately from HOL analysis.