{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ocfs2: cluster: don't sleep while holding o2hb_live_lock in o2hb_region_pin()  Patch series \"ocfs2: cluster: o2hb_region_pin() fixes\", v2.  This series fixes three related issues in o2hb_region_pin(), all are from the original implementation in commit: 58a3158a5d17 (\"ocfs2/cluster: Pin/unpin o2hb regions\"):  1) It is called with o2hb_live_lock (a spinlock) held, but the    underlying configfs_depend_item() sleeps (takes inode rwsem and    pins the filesystem).  This triggers BUG under    CONFIG_DEBUG_ATOMIC_SLEEP.  2) When called from the configfs drop_item callback, it creates a    lock order inversion: parent inode_lock -\u003e configfs root    inode_lock, which can deadlock against subsystem unregistration    paths taking root -\u003e parent.  3) If pinning fails partway through o2hb_region_inc_user(), the    o2hb_dependent_users counter is leaked and partially-pinned    regions are never released, leaving heartbeat regions    unprotected on subsequent mounts.  Patch 1 reworks o2hb_region_pin() to drop o2hb_live_lock across each sleeping configfs_depend_item() call, using a config_item reference to keep the region alive while unlocked.  Patch 2 adds a from_callback parameter to select configfs_depend_item_unlocked() when called from configfs context, avoiding the inode_lock nesting.  Patch 3 fixes the error path in o2hb_region_inc_user() to unpin and decrement the counter on failure.   This patch (of 3):  o2hb_region_pin() is always called with the o2hb_live_lock spinlock held (from o2hb_region_inc_user() and o2hb_heartbeat_group_drop_item()), but it calls o2nm_depend_item() -\u003e configfs_depend_item(), which sleeps: it pins the configfs filesystem and takes the configfs root inode rwsem.  Under CONFIG_DEBUG_ATOMIC_SLEEP this triggers:    BUG: sleeping function called from invalid context at kernel/locking/rwsem.c   in_atomic(): 1, ... name: mount.ocfs2     down_write     configfs_depend_item     o2hb_region_pin     o2hb_region_inc_user     o2hb_register_callback     dlm_register_domain_handlers     ...     ocfs2_dlm_init     ocfs2_mount_volume     ocfs2_fill_super  Rework o2hb_region_pin() to pin one region at a time with the lock dropped across the sleeping call: under o2hb_live_lock find the next eligible region and take a config_item reference to keep it alive, drop the lock, call o2nm_depend_item(), then retake the lock and record the pin.  The config_item_put() is done with the lock released as well, since o2hb_region_release() also acquires o2hb_live_lock and can sleep.  The region list may change while unlocked, so the scan restarts from the top after each pin.  Local heartbeat still pins only the matching region; global heartbeat pins all eligible regions.  The unpin path is unaffected: configfs_undepend_item() only takes a spinlock and does not sleep.",
  "id": "DEBIAN-CVE-2026-89491",
  "modified": "2026-09-15T08:47:35.514024869Z",
  "published": "2026-09-11T20:19:30.943Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-89491"
    }
  ],
  "upstream": [
    "CVE-2026-89491"
  ]
}