CVE-2026-53049
published 2026-06-24CVE-2026-53049: In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.51%
40.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
gfs2: add some missing log locking
Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(),
gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock,
but these functions require exclusion against concurrent transactions.
To fix that, add a non-locking __gfs2_log_flush() function. Then, in
gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log
flushing functions and __gfs2_log_flush().
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < 3b28eb75afe520972bacc833850c2b30aa0824cd | 3b28eb75afe520972bacc833850c2b30aa0824cd |
| linux | linux | >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < ca95342cb1b39062a03c115830286f0a426053d5 | ca95342cb1b39062a03c115830286f0a426053d5 |
| linux | linux | >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < bf5fcd9c37c2546beaf7b401d31aefd89017dc3d | bf5fcd9c37c2546beaf7b401d31aefd89017dc3d |
| linux | linux | >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < f2f225cf505ac016132ded21690f3ba0a080a4e8 | f2f225cf505ac016132ded21690f3ba0a080a4e8 |
| linux | linux | >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < 49d9be0722da3a4a893ba905720cba1921834ec3 | 49d9be0722da3a4a893ba905720cba1921834ec3 |
| linux | linux | >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < 98e8bf249c790d56de1abc4a5f8bd68035a00921 | 98e8bf249c790d56de1abc4a5f8bd68035a00921 |
| linux | linux | >= 5e4c7632aae1cce137792647f4fb6f599d1da893 < fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8 | fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8 |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 7.0.9 gfs2 gfs2_logd sd_log_flush_lock locking (WID-SEC-2026-2077)
vuldb·2026-07-19·CVSS 9.8
CVE-2026-53049 [CRITICAL] Linux Kernel up to 7.0.9 gfs2 gfs2_logd sd_log_flush_lock locking (WID-SEC-2026-2077)
A vulnerability was found in Linux Kernel up to 7.0.9. It has been rated as critical. Affected by this issue is the function gfs2_logd of the component gfs2. This manipulation of the argument sd_log_flush_lock causes improper locking.
The identification of this vulnerability is CVE-2026-53049. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
GHSA
In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and
ghsa_unreviewed·2026-06-24
CVE-2026-53049 In the Linux kernel, the following vulnerability has been resolved: gfs2: add some missing log locking Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(), gfs2_ail1_wait(), and
In the Linux kernel, the following vulnerability has been resolved:
gfs2: add some missing log locking
Function gfs2_logd() calls the log flushing functions gfs2_ail1_start(),
gfs2_ail1_wait(), and gfs2_ail1_empty() without holding sdp->sd_log_flush_lock,
but these functions require exclusion against concurrent transactions.
To fix that, add a non-locking __gfs2_log_flush() function. Then, in
gfs2_logd(), take sdp->sd_log_flush_lock before calling the above mentioned log
flushing functions and __gfs2_log_flush().
Red Hat
kernel: gfs2: add some missing log locking
vendor_redhat·2026-06-24·CVSS 7.0
CVE-2026-53049 [MEDIUM] CWE-414 kernel: gfs2: add some missing log locking
kernel: gfs2: add some missing log locking
A flaw was found in the Linux kernel's Global File System 2 (GFS2) component. The `gfs2_logd()` function, responsible for log flushing, calls several log flushing functions without holding the required lock. This omission allows concurrent transactions to access shared resources without proper exclusion, which could lead to race conditions. Such conditions may result in system instability or data corruption, potentially causing a Denial of Service (DoS).
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Affected
Package: kernel (Red Hat Enterprise Linux 8) - A
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/3b28eb75afe520972bacc833850c2b30aa0824cdhttps://git.kernel.org/stable/c/49d9be0722da3a4a893ba905720cba1921834ec3https://git.kernel.org/stable/c/98e8bf249c790d56de1abc4a5f8bd68035a00921https://git.kernel.org/stable/c/bf5fcd9c37c2546beaf7b401d31aefd89017dc3dhttps://git.kernel.org/stable/c/ca95342cb1b39062a03c115830286f0a426053d5https://git.kernel.org/stable/c/f2f225cf505ac016132ded21690f3ba0a080a4e8https://git.kernel.org/stable/c/fe2c8d051150b90b3ccb85f89e3b1d636cb88ec8
2026-06-24
Published