PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80808 Linux CVE debrief

The Linux kernel has a vulnerability in the ext4 filesystem where a saturated xattr cache entry can cause a task to spin indefinitely, holding the parent directory's i_rwsem and blocking concurrent rmdir callers. This issue can occur when a corrupted filesystem violates the invariant that a reusable entry has a reference count below EXT4_XATTR_REFCOUNT_MAX. The fix checks the untrusted on-disk count before incrementing it, avoiding overflow, and clears MBE_REUSABLE_B when it is already saturated.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-04
Original CVE updated
2026-09-04
Advisory published
2026-09-04
Advisory updated
2026-09-04

Who should care

Defenders responsible for Linux kernel systems, particularly those using ext4 filesystems, should assess exposure and prioritize patching. System administrators and security teams should be aware of potential filesystem corruption or abnormal behavior in systems using the Linux kernel.

Why it matters

The Linux kernel vulnerability in the ext4 filesystem can cause a task to spin indefinitely, holding the parent directory's i_rwsem and blocking concurrent rmdir callers. Defenders should prioritize verifying and applying patches, enhancing monitoring, and reviewing security measures.

  • Verify Linux kernel versions and ext4 filesystem configurations to prevent similar issues.
  • Enhance monitoring for signs of potential filesystem corruption or abnormal behavior.
  • Prioritize patching for Linux kernel versions affected by this vulnerability.
  • Review and update security measures for critical systems.

Technical summary

The Linux kernel has a vulnerability in the ext4 filesystem where a saturated xattr cache entry can cause a task to spin indefinitely. This issue can occur when a corrupted filesystem violates the invariant that a reusable entry has a reference count below EXT4_XATTR_REFCOUNT_MAX. The fix checks the untrusted on-disk count before incrementing it, avoiding overflow, and clears MBE_REUSABLE_B when it is already saturated.

Defensive priority

Defenders should prioritize verifying and applying patches for Linux kernel versions affected by this vulnerability, particularly those related to ext4 filesystem handling. They should also enhance monitoring for signs of potential filesystem corruption or abnormal behavior in systems using the Linux kernel.

Recommended defensive actions

  • Verify and apply patches for Linux kernel versions affected by this vulnerability.
  • Enhance monitoring for signs of potential filesystem corruption or abnormal behavior in systems using the Linux kernel.
  • Review and update ext4 filesystem configurations to prevent similar issues.
  • Consider implementing additional security measures for critical systems.
  • Perform an asset inventory to identify potentially affected systems.
  • Establish a rollback/change window plan for remediation.
  • Track and verify remediation efforts through source tracking.

Evidence notes

The issue was resolved by checking the untrusted on-disk count before incrementing it and clearing MBE_REUSABLE_B when saturated. Testing with a QEMU harness and guest parameters showed that current unpatched Linux hung in 6 of 8 trials, while the patched kernel completed 28 of 28 trials without a hung-task report.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80808 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80808

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80808 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80808

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/119a2f053242ed75bdd2ebc95baf3ae7db6ccacf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4902a5cba21aeaf91e6b29e20e0967a5f6abdcd9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/54b6bd40898de7906acb2bccc9a96d1b8e6b4323

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/55ee6533c1db7f7656fa8dd19637f3f8b8c08dc5

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/61631352a5b405c89be579de00903b72e6888aa4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8865cd664484517703df5c18a965dc3227572b87

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/889ec86464d261f026f6c334040cfc6c58c99d58

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a40c45268f4358207aa9c53764fed2e05f62986a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.