CVE-2026-23036
Description
An ABBA deadlock vulnerability was found in the Linux kernel's Btrfs filesystem. When btrfs_read_locked_inode() fails to lookup an inode, it calls iget_failed() while still holding a read-locked btree leaf. Since iget_failed() triggers inode eviction which needs the delayed_node mutex, and delayed inode updates hold the mutex while modifying the btree, a circular lock dependency occurs leading to deadlock.
Statement
This deadlock was discovered by syzbot and affects Btrfs filesystem operations that fail during inode lookup. The lock order violation between btrfs-tree-00 and delayed_node->mutex can cause the system to hang. Triggering requires specific error conditions during inode operations that cause the lookup to fail.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 5.5 | N/A | N/A |
| Attack Vector | Local | N/A | N/A |
| Attack Complexity | Low | N/A | N/A |
| Privileges Required | Low | N/A | N/A |
| User Interaction | None | N/A | N/A |
| Scope | Unchanged | N/A | N/A |
| Confidentiality | None | N/A | N/A |
| Integrity Impact | None | N/A | N/A |
| Availability Impact | High | N/A | N/A |
Vector
Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Integrity,Confidentiality,Other
Technical Impact: Modify Application Data; Read Application Data; Alter Execution Logic
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.