CVE-2026-68096: audit: fix recursive locking deadlock in audit_dupe_exe()

Published Aug 10, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

audit: fix recursive locking deadlock in auditdupeexe()

A deadlock occurs in the audit subsystem when duplicating executable-related rules.

When a file is moved (e.g., via dorenameat2()), the VFS layer locks the parent directory (IMUTEXPARENT), which synchronously triggers an fsnotifymove event. If an existing executable audit rule matches the file being moved, the audit subsystem catches this event and calls auditdupeexe() to duplicate the watch and update the rule. Then, auditallocmark() would call kernpathparent() to resolve the path, leading to a blind attempt to acquire the exact same IMUTEXPARENT lock already held by the task, resulting in the following recursive locking deadlock:

============================================ WARNING: possible recursive locking detected 6.12.0-55.27.1.el100.x8664+debug #1 Not tainted -------------------------------------------- mv/5099 is trying to acquire lock: ffff888132845358 (&inode->isb->stype->imutexdirkey/1){+.+.}-{3:3}, at: kernpathlocked+0x10a/0x2f0

but task is already holding lock: ffff888132846b58 (&inode->isb->stype->imutexdirkey/1){+.+.}-{3:3}, at: locktwodirectories+0x13f/0x2b0

other info that might help us debug this: Possible unsafe locking scenario:

CPU0 ---- lock(&inode->isb->stype->imutexdirkey/1); lock(&inode->isb->stype->imutexdirkey/1);

DEADLOCK

May be due to missing lock nesting notation

6 locks held by mv/5099: #0: ffff888112a9c440 (sbwriters#13) at: dorenameat2+0x34c/0xbc0 #1: ffff888112a9c790 (&type->svfsrenamekey#3) at: dorenameat2+0x415/0xbc0 #2: ffff888132846b58 (&inode->isb->stype->imutexdirkey/1) at: locktwodirectories+0x13f/0x2b0 #3: ffff888132845358 (&inode->isb->stype->imutexdirkey/5) at: locktwodirectories+0x175/0x2b0 #4: ffffffffb3a1fb10 (&fsnotifymarksrcu) at: fsnotify+0x454/0x28a0 #5: ffffffffaf886230 (auditfiltermutex) at: auditupdatewatch+0x36/0x11e0

stack backtrace: Call Trace: <TASK> dumpstacklvl+0x6f/0xb0 printdeadlockbug.cold+0xbd/0xca validatechain+0x83a/0xf00 lockacquire+0xcac/0x1d20 lockacquire.part.0+0x11b/0x360 downwritenested+0x9f/0x230 kernpathlocked+0x10a/0x2f0 kernpathlocked+0x26/0x40 auditallocmark+0xfb/0x4f0 auditdupeexe+0x6c/0xe0 auditduperule+0x6c2/0xc00 auditupdatewatch+0x4cc/0x11e0 auditwatchhandleevent+0x12c/0x1b0 sendtogroup+0x5d0/0x8b0 fsnotify+0x615/0x28a0 fsnotifymove+0x1d8/0x630 vfsrename+0xdcd/0x1df0 dorenameat2+0x9d4/0xbc0 x64sysrenameat+0x192/0x260 dosyscall64+0x92/0x180 entrySYSCALL64afterhwframe+0x76/0x7e RIP: 0033:0x7f0491fe8c4e Code: 0f 1f 40 00 48 8b 15 c1 e1 16 00 f7 d8 64 89 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 08 01 00 00 0f 05 <48> 3d 00 f0 ff ff 77 0a c3 66 0f 1f 84 00 00 00 00 00 48 8b 15 89 RSP: 002b:00007ffc7210bf38 EFLAGS: 00000246 ORIGRAX: 0000000000000108 RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f0491fe8c4e RDX: 0000000000000003 RSI: 00007ffc7210e6c8 RDI: 00000000ffffff9c RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000001 R10: 00005575eb2dae2a R11: 0000000000000246 R12: 00005575eb2dae2a R13: 00007ffc7210e6c8 R14: 0000000000000003 R15: 00000000ffffff9c </TASK>

The aforementioned deadlock can be consistently reproduced by running the script below:

audit-dupe-exe-deadlock.sh -------------------------- #!/bin/bash auditctl -D mkdir -p /tmp/foo touch /tmp/file auditctl -a always,exit -F exe=/tmp/file -F path=/tmp/file -S all -k dr mv /tmp/file /tmp/foo/file rm -Rf /tmp/foo

This patch fixes the issue by introducing struct auditwatchctx to pass the fsnotify event context down to auditallocmark(). By utilizing the already-resolved directory inode provided by the event, we bypass the kernpathparent() path resol ---truncated---

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Linux kernel audit subsystem (audit_dupe_exe recursive locking fix) to a version that resolves this vulnerability.

    Patch audit: fix recursive locking deadlock in audit_dupe_exe()
  2. Operational

    Reboot/restart the system after applying the Linux kernel audit subsystem patch (audit: fix recursive locking deadlock in audit_dupe_exe()) so the updated kernel is active.

Event History

Aug 10, 2026
CVE Published
via MITRE·11:58 AM
Data Sourced
via MITRE·11:58 AM
Description
Data Sourced
via NVD·01:19 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-68096?

CVE-2026-68096 has a risk rating of 21, indicating a serious vulnerability that could lead to deadlock conditions.

2

How do I fix CVE-2026-68096?

To fix CVE-2026-68096, upgrade to the latest patched version of the Linux kernel where this vulnerability has been resolved.

3

What systems are impacted by CVE-2026-68096?

CVE-2026-68096 affects Linux kernel users, particularly those utilizing the audit subsystem for executable-related rules.

4

What type of vulnerability is CVE-2026-68096?

CVE-2026-68096 is a deadlock vulnerability within the audit subsystem of the Linux kernel.

5

When was CVE-2026-68096 published?

CVE-2026-68096 was published on August 10, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203