CVE-2026-68150

Source
https://cve.org/CVERecord?id=CVE-2026-68150
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68150.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-68150
Downstream
Published
2026-08-10T11:59:15.647Z
Modified
2026-08-25T03:51:50.830977618Z
Summary
fs/super: fix emergency thaw double-unlock of s_umount
Details

In the Linux kernel, the following vulnerability has been resolved:

fs/super: fix emergency thaw double-unlock of s_umount

dothawall() iterates over all superblocks via __iteratesupers() with SUPERITEREXCL, which acquires sumount exclusively before calling the callback and releases it afterwards. However, the callback dothawallcallback() calls thawsuperlocked() which unconditionally releases sumount on every code path. This results in a second unlock attempt in __iteratesupers() that corrupts the rwsem state, triggering a DEBUGRWSEMS warning:

[ 182.601148] sysrq: Emergency Thaw of all frozen filesystems [ 182.601865] ------------[ cut here ]------------ [ 182.602375] DEBUGRWSEMSWARNON((rwsemowner(sem) != current) && !rwsemtestoflags(sem, RWSEMNONSPINNABLE)): count = 0x0, magic = 0xffff99b1011e5870, owner = 0x0, curr 0xffff99b101b06c80, list not empty [ 182.603817] WARNING: kernel/locking/rwsem.c:1412 at upwrite+0xa3/0x170, CPU#2: kworker/2:1/53 [ 182.604578] Modules linked in: [ 182.604864] CPU: 2 UID: 0 PID: 53 Comm: kworker/2:1 Not tainted 7.2.0-rc4-00001-gbd3bd93ea98a-dirty #4 PREEMPT(lazy) [ 182.605711] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1kylin1 04/01/2014 [ 182.606417] Workqueue: events dothawall [ 182.606750] RIP: 0010:up_write+0xaf/0x170 [ 182.607076] Code: 19 3a 92 48 0f 44 c2 48 8b 55 08 48 8b 55 00 4c 8b 45 08 48 8b 55 00 48 8d 3d ad 91 e0 01 48 8b 4d 20 50 48 c7 c6 f0 8c 26 92 <67> 48 0f b9 3a e8 d7 93 4e 00 58 eb 81 48 83 7f 18 00 48 c7 c2 8d [ 182.608563] RSP: 0018:ffffb670001d7e08 EFLAGS: 00010246 [ 182.609007] RAX: ffffffff92349e8d RBX: 0000000000000000 RCX: ffff99b1011e5870 [ 182.609595] RDX: 0000000000000000 RSI: ffffffff92268cf0 RDI: ffffffff92914d10 [ 182.610283] RBP: ffff99b1011e5870 R08: 0000000000000000 R09: ffff99b101b06c80 [ 182.610847] R10: ffff99b10139a808 R11: fefefefefefefeff R12: 0000000000000000 [ 182.611414] R13: ffffffff90cf74d0 R14: 0000000000000000 R15: ffff99b1011e5800 [ 182.612009] FS: 0000000000000000(0000) GS:ffff99b1eaaee000(0000) knlGS:0000000000000000 [ 182.612670] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 182.613146] CR2: 00000000005c631c CR3: 00000000013ee000 CR4: 00000000000006f0 [ 182.613722] Call Trace: [ 182.613946] <TASK> [ 182.614130] __iteratesupers+0x128/0x150 [ 182.614463] dothawall+0x1b/0x30 [ 182.614759] processscheduled_works+0xbb/0x3f0 [ 182.615150] ? __pfxworkerthread+0x10/0x10 [ 182.615499] worker_thread+0x129/0x270 [ 182.615816] ? __pfxworkerthread+0x10/0x10 [ 182.616201] kthread+0xe2/0x120 [ 182.616469] ? __pfxkthread+0x10/0x10 [ 182.616792] retfrom_fork+0x15b/0x240 [ 182.617115] ? __pfxkthread+0x10/0x10 [ 182.617426] retfromforkasm+0x1a/0x30 [ 182.617761] </TASK> [ 182.617968] ---[ end trace 0000000000000000 ]--- [ 182.618412] Emergency Thaw complete

Fix this by switching to SUPERITERUNLOCKED and acquiring sumount in the callback via superlockexcl() before calling thawsuperlocked(). This matches the locking pattern expected by thawsuper_locked() and eliminates the double unlock.

While at it, remove the dead 'return;' at the end of dothawall_callback().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68150.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
96a7883817a29fcbb46f70f0302ed455f7203c74
Fixed
79e04370657a2581e3189f9c7fc166e7c4fbab3a
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
2992476528aeecbaee17ba0a6396a817481205a3
Fixed
c78e38745ff1b0457c4551e7f75ea15842df1169
Fixed
64017df6e61a3ce7159cee284109b92009985361
Fixed
503d67fbaec6fdeaba391cb497675071db9d16ea

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68150.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.42
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68150.json"