Medium [CVE-2026-68150] Linux kernel: Denial of Service due to double-unlock in filesystem thaw operation
This medium-severity Red Hat Linux advisory covers CVE-2026-68150.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
In the Linux kernel, the following vulnerability has been resolved: fs/super: fix emergency thaw double-unlock of s_umount do_thaw_all() iterates over all superblocks via __iterate_supers() with SUPER_ITER_EXCL, which acquires s_umount exclusively before calling the callback and releases it afterwards.
However, the callback do_thaw_all_callback() calls thaw_super_locked() which unconditionally releases s_umount on every code path.
- < 182.601148
- < 182.601865
- < 182.602375
- < 182.603817
- < 182.604578
- < 182.604864
- < 7.2.0-rc4
- < 182.605711
- < 1.13.0-1kylin1
- < 182.606417
- < 182.606750
- < 182.607076
- < 182.608563
- < 182.609007
- < 182.609595
- < 182.610283
- < 182.610847
- < 182.611414
- < 182.612009
- < 182.612670
- < 182.613146
- < 182.613722
- < 182.613946
- < 182.614130
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Mitigation
The source record does not include mitigation steps. That is not a statement that no fix exists — read the vendor advisory below for the authoritative guidance.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.