Impact
The vulnerability originates in the OCFS2 cluster filesystem, where the o2hb_region_pin() function is invoked while holding the spinlock o2hb_live_lock. Inside this function a call to configfs_depend_item() can sleep, violating the non-preemptive lock-holding contract and triggering a BUG under CONFIG_DEBUG_ATOMIC_SLEEP. Additionally, when called from the configfs drop_item callback, the code establishes a lock‑order inversion that can deadlock kernel unregistration paths. Finally, a failure during pinning leaks a counter and leaves heartbeat regions permanently pinned, compromising the integrity of subsequent mounts. These issues together can interrupt kernel operation, freeze the system or de‑protect critical namespace data.
Affected Systems
Any Linux kernel that includes the OCFS2 cluster filesystem is impacted, as the flaw resides in the o2hb_region_pin implementation. The patch series applies to all builds that contain the original code path, and no specific version information was provided in the CVE data. Therefore, affected builds are unspecified beyond the presence of the OCFS2 cluster filesystem.
Risk and Exploitability
The CVSS score of 4.4 categorises the flaw as a low severity issue, < 1%, while the vulnerability is not listed in the CISA KEV catalog, indicating low current exploitation pressure. Attackability is largely local: who can trigger the problematic code path must have the ability to mount an OCFS2 filesystem, modify its configuration via configfs, or load the module in an unpatched kernel. The resultant denial of service is achieved by a kernel BUG or deadlock rather than by privilege escalation or data exfiltration.
OpenCVE Enrichment
Debian DSA