CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026071934-CVE-2026-64164-a963@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() The trace event btrfs_sync_file() is called in an atomic context (all trace events are) and its call to dput(), which is needed due to the call to dget_parent(), can sleep, triggering a kernel splat. This can be reproduced by enabling the trace event and running btrfs/056 from fstests for example. The splat shown in dmesg is the following: [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970 [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io [53.988] preempt_count: 2, expected: 0 [53.967] RCU nest depth: 0, expected: 0 [53.943] Preemption disabled at: [53.944] [<0000000000000000>] 0x0 [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G W 7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full) [54.070] Tainted: [W]=WARN [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014 [54.072] Call Trace: [54.074] <TASK> [54.076] dump_stack_lvl+0x56/0x80 [54.079] __might_resched.cold+0xd6/0x10f [54.072] dput.part.0+0x24/0x110 [54.078] trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs] [54.089] btrfs_sync_file+0x1ed/0x530 [btrfs] [54.087] ? __handle_mm_fault+0x8ae/0xed0 [54.089] btrfs_do_write_iter+0x172/0x210 [btrfs] [54.091] vfs_write+0x21f/0x450 [54.094] __x64_sys_pwrite64+0x8d/0xc0 [54.096] ? do_user_addr_fault+0x20c/0x670 [54.099] do_syscall_64+0x60/0xf20 [54.092] ? clear_bhb_loop+0x60/0xb0 [54.094] entry_SYSCALL_64_after_hwframe+0x76/0x7e So stop using dget_parent() and dput() and access the parent dentry directly as dentry->d_parent. This is also what ext4 is doing in its equivalent trace event ext4_sync_file_enter(). The Linux kernel CVE team has assigned CVE-2026-64164 to this issue. Affected and fixed versions =========================== Issue introduced in 6.6.136 with commit c09a7446aab5773f38d6abb25fce99b8e1dfbc97 and fixed in 6.6.142 with commit 26b2290baaf6da6add0f782a100766e686a33f4f Issue introduced in 6.12.83 with commit 32372781d664a9b03c40343e96c29d0a6139f97d and fixed in 6.12.92 with commit 12a0487945c09760a5968d9333383014ea294117 Issue introduced in 6.18.24 with commit 2e4adfaec97ee053ad1bdfb5036845e66f7e0d8a and fixed in 6.18.34 with commit c32a7e0e3c73c1c0768556a56bd78de9f7b83780 Issue introduced in 7.0 with commit a85b46db143fda5869e7d8df8f258ccef5fa1719 and fixed in 7.0.11 with commit 0a96d9a85cd2240481297156b9bb72e10b7a8036 Issue introduced in 7.0 with commit a85b46db143fda5869e7d8df8f258ccef5fa1719 and fixed in 7.1 with commit c73370c677646e86fc4b1780fb07027bdf847375 Issue introduced in 6.19.14 with commit d110d7cdb045715c0b45b0dfd974525bb38f653d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64164 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: include/trace/events/btrfs.h Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/d78b0a80eac36879ef5478707135c446920e134b https://git.kernel.org/stable/c/4361954f0e158af0530caa1e57f12b531be4658f https://git.kernel.org/stable/c/6279992c9ba2774901c9d4dd4a481162e2534714 https://git.kernel.org/stable/c/26b2290baaf6da6add0f782a100766e686a33f4f https://git.kernel.org/stable/c/12a0487945c09760a5968d9333383014ea294117 https://git.kernel.org/stable/c/c32a7e0e3c73c1c0768556a56bd78de9f7b83780 https://git.kernel.org/stable/c/0a96d9a85cd2240481297156b9bb72e10b7a8036 https://git.kernel.org/stable/c/c73370c677646e86fc4b1780fb07027bdf847375