The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade Debian:12 linux-6.12 to version 6.12.111-1~deb12u1 or higher.
Note: Versions mentioned in the description apply only to the upstream linux-6.12 package and not the linux-6.12 package as distributed by Debian.
See How to fix? for Debian:12 relevant fixed versions and status.
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: fix circular locking dependency in ocfs2_init_acl()
A lockdep warning indicates a circular locking dependency between
&oi->ip_xattr_sem and &journal->j_trans_barrier:
WARNING: possible circular locking dependency detected is trying to acquire lock: (&oi->ip_xattr_sem){++++}-{4:4}, at: ocfs2_init_acl+0x2fd/0x7e0 fs/ocfs2/acl.c:367
but task is already holding lock: (&journal->j_trans_barrier){.+.+}-{4:4}, at: ocfs2_start_trans+0x3ab/0x700 fs/ocfs2/journal.c:369
The deadlock involves two code paths: Path 1 (setxattr) where
ocfs2_xattr_set() acquires ip_xattr_sem (write) and then starts a
transaction, which acquires j_trans_barrier (read); and Path 2
(mkdir/mknod) where ocfs2_mknod() starts a transaction (j_trans_barrier
read) and then calls ocfs2_init_acl(), which attempts to acquire
ip_xattr_sem (read) on the parent directory to retrieve the default ACL.
Because rw_semaphores are subject to writer priority, a pending writer on
j_trans_barrier (e.g., the journal commit thread) can cause Path 1 to
block, while Path 2 is blocked waiting for Path 1 to release
ip_xattr_sem.
The patch fixes the lock ordering by precomputing the ACL state before
starting the OCFS2 transaction, while preserving POSIX ACL storage
semantics and the existing inode/security initialization order. By reading
the parent directory's default ACL and preparing the new inode's ACLs
outside the transaction, ip_xattr_sem is always acquired before
j_trans_barrier.
struct ocfs2_acl_state encapsulates the prepared ACL state, while
ocfs2_acl_init_prepare() and ocfs2_acl_init_release() avoid code
duplication between ocfs2_mknod() and ocfs2_init_security_and_acl().
ocfs2_calc_xattr_init() and ocfs2_init_acl() use this precomputed
state, removing internal ip_xattr_sem acquisition and redundant disk
reads.
Additionally, remove the ip_xattr_sem acquisition from
ocfs2_xattr_set_handle(). This function is only used while initializing a
new inode that has not yet been inserted into the inode hash or attached to
a dentry, meaning there is no risk of concurrent access and the lock is
unnecessary.