Impact
A deadlock condition exists in the ext4 filesystem’s extended attribute cache handling. When a user process performs an extended attribute lookup while the kernel’s eviction thread is concurrently removing the same inode, the two threads wait on each other’s references, resulting in an ABBA deadlock. The revised implementation introduces a non‑blocking inode lookup and returns an error instead of waiting, eliminating the cycle and preventing the kernel from hanging during normal operation.
Affected Systems
The issue affects Linux kernels that implement ext4 with the legacy xattr cache path, prior to the commit that adds the EXT4_IGET_NOWAIT flag. All distributions employing those kernels are vulnerable until the patch is applied, regardless of kernel version number.
Risk and Exploitability
The EPSS score is listed as < 1 % and the vulnerability is not in the CISA KEV catalog, indicating a low probability of widespread exploitation. An attacker could potentially trigger the deadlock by submitting concurrent extended attribute operations—either intentionally or as a side effect of workload patterns—leading to a system halt or degraded service. The attack vector is inferred to be in‑system activity that exercises the xattr subsystem, such as stress tests, backup utilities, or malicious code that manipulates file attributes.
OpenCVE Enrichment