CVE-2026-93268

In the Linux kernel, the following vulnerability has been resolved: ext4: skip extra isize expansion during mount to prevent deadlock ext4_try_to_expand_extra_isize() is called from __ext4_mark_inode_dirty() while holding an active jbd2 handle. During mount (!SB_ACTIVE), the expand path may move xattrs to external blocks and release ea_inodes via iput(). When !SB_ACTIVE, iput() calls write_inode_now() which acquires s_writepages_rwsem, creating a circular lock dependency: s_writepages_rwsem --> jbd2_handle --> xattr_sem --> s_writepages_rwsem This can be triggered via: ext4_process_orphan() -> ext4_truncate() -> ext4_mark_inode_dirty() -> ext4_try_to_expand_extra_isize() or: ext4_evict_inode() -> ext4_mark_inode_dirty() -> ext4_try_to_expand_extra_isize() Skip expansion when !SB_ACTIVE. This is a minor loss of functionality (extra isize won't grow for these inodes during mount), which e2fsck can resolve later if needed.

Package Linux Kernel
Published 2026-09-24
Last modified 2026-09-24
Patch available
Yes

Affected versions

Linux kernel versions 4.7 and later are affected. Fixed in 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.110, 6.18.52, 7.2.6, 7.3-rc1 and their respective stable series.

Affected from
≥ 4.7
Fixed in
✓ 5.10.270 5.10.x ✓ 5.15.221 5.15.x ✓ 6.1.188 6.1.x ✓ 6.6.157 6.6.x ✓ 6.12.110 6.12.x ✓ 6.18.52 6.18.x ✓ 7.2.6 7.2.x ✓ 7.3-rc1

Frequently asked questions

  • What is CVE-2026-93268?

    CVE-2026-93268 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 4.7 onward and has been patched in 5.10.270, 5.15.221, 6.1.188 and others. CVE-2026-93268 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-93268?

    Yes. CVE-2026-93268 has been patched. Fixed versions include 5.10.270, 5.15.221, 6.1.188 and others. If you are running Linux kernel 4.7 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-93268 actively exploited?

    No. CVE-2026-93268 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.