In the Linux kernel, the following vulnerability has been resolved:
fs/super: fix emergency thaw double-unlock of s_umount
dothawall() iterates over all superblocks via __iteratesupers() with SUPERITEREXCL, which acquires sumount exclusively before calling the callback and releases it afterwards. However, the callback dothawallcallback() calls thawsuperlocked() which unconditionally releases sumount on every code path. This results in a second unlock attempt in __iteratesupers() that corrupts the rwsem state, triggering a DEBUGRWSEMS warning:
[ 182.601148] sysrq: Emergency Thaw of all frozen filesystems [ 182.601865] ------------[ cut here ]------------ [ 182.602375] DEBUGRWSEMSWARNON((rwsemowner(sem) != current) && !rwsemtestoflags(sem, RWSEMNONSPINNABLE)): count = 0x0, magic = 0xffff99b1011e5870, owner = 0x0, curr 0xffff99b101b06c80, list not empty [ 182.603817] WARNING: kernel/locking/rwsem.c:1412 at upwrite+0xa3/0x170, CPU#2: kworker/2:1/53 [ 182.604578] Modules linked in: [ 182.604864] CPU: 2 UID: 0 PID: 53 Comm: kworker/2:1 Not tainted 7.2.0-rc4-00001-gbd3bd93ea98a-dirty #4 PREEMPT(lazy) [ 182.605711] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1kylin1 04/01/2014 [ 182.606417] Workqueue: events dothawall [ 182.606750] RIP: 0010:up_write+0xaf/0x170 [ 182.607076] Code: 19 3a 92 48 0f 44 c2 48 8b 55 08 48 8b 55 00 4c 8b 45 08 48 8b 55 00 48 8d 3d ad 91 e0 01 48 8b 4d 20 50 48 c7 c6 f0 8c 26 92 <67> 48 0f b9 3a e8 d7 93 4e 00 58 eb 81 48 83 7f 18 00 48 c7 c2 8d [ 182.608563] RSP: 0018:ffffb670001d7e08 EFLAGS: 00010246 [ 182.609007] RAX: ffffffff92349e8d RBX: 0000000000000000 RCX: ffff99b1011e5870 [ 182.609595] RDX: 0000000000000000 RSI: ffffffff92268cf0 RDI: ffffffff92914d10 [ 182.610283] RBP: ffff99b1011e5870 R08: 0000000000000000 R09: ffff99b101b06c80 [ 182.610847] R10: ffff99b10139a808 R11: fefefefefefefeff R12: 0000000000000000 [ 182.611414] R13: ffffffff90cf74d0 R14: 0000000000000000 R15: ffff99b1011e5800 [ 182.612009] FS: 0000000000000000(0000) GS:ffff99b1eaaee000(0000) knlGS:0000000000000000 [ 182.612670] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 182.613146] CR2: 00000000005c631c CR3: 00000000013ee000 CR4: 00000000000006f0 [ 182.613722] Call Trace: [ 182.613946] <TASK> [ 182.614130] __iteratesupers+0x128/0x150 [ 182.614463] dothawall+0x1b/0x30 [ 182.614759] processscheduled_works+0xbb/0x3f0 [ 182.615150] ? __pfxworkerthread+0x10/0x10 [ 182.615499] worker_thread+0x129/0x270 [ 182.615816] ? __pfxworkerthread+0x10/0x10 [ 182.616201] kthread+0xe2/0x120 [ 182.616469] ? __pfxkthread+0x10/0x10 [ 182.616792] retfrom_fork+0x15b/0x240 [ 182.617115] ? __pfxkthread+0x10/0x10 [ 182.617426] retfromforkasm+0x1a/0x30 [ 182.617761] </TASK> [ 182.617968] ---[ end trace 0000000000000000 ]--- [ 182.618412] Emergency Thaw complete
Fix this by switching to SUPERITERUNLOCKED and acquiring sumount in the callback via superlockexcl() before calling thawsuperlocked(). This matches the locking pattern expected by thawsuper_locked() and eliminates the double unlock.
While at it, remove the dead 'return;' at the end of dothawall_callback().
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68150.json"
}