CVE-2026-68459

Summary

In the Linux kernel, the following vulnerability has been resolved:

f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()

When we mount device w/ gc_merge mount option, we may suffer below potential deadlock:

Kworker GC trehad Truncator

  • f2fs_write_cache_pages
  • f2fs_write_single_data_page
  • f2fs_do_write_data_page
  • folio_start_writeback — set writeback flag on folio
  • f2fs_outplace_write_data : cached folio in internal bio cache
  • f2fs_balance_fs
  • wake_up(gc_thread) : wake up gc thread to run foreground GC
  • finish_wait(fggc_wq) : wait on the waitqueue — wait on GC thread to finish the work - truncate_inode_pages_range - __filemap_get_folio(, FGP_LOCK) — lock folio - truncate_inode_partial_folio - folio_wait_writeback — wait on writeback being cleared - do_garbage_collect - move_data_page - f2fs_get_lock_data_folio - lock on folio — blocked on folio's lock

In order to avoid such deadlock, let's call below functions to commit cached bios in GC_MERGE path of f2fs_balance_fs() as the same as we did in NOGC_MERGE path.

  • f2fs_submit_merged_write(sbi, DATA);
  • f2fs_submit_all_merged_ipu_writes(sbi);

Affected Software

VendorProductVersion RangeStatus
LinuxLinux351df4b201157351c7d26bf12c3eeb9dbce98854 < 8071500a8124e5a6d47d901a8d5ffd91743107a1affected
LinuxLinux351df4b201157351c7d26bf12c3eeb9dbce98854 < eb02f218aacb36365e0ca2339cbae81fb05d31a5affected
LinuxLinux351df4b201157351c7d26bf12c3eeb9dbce98854 < 1436031b33fa23ab1ce7df5bc5500093413e8acfaffected
LinuxLinux351df4b201157351c7d26bf12c3eeb9dbce98854 < b885c7783c19c36c7bf899492a0bffcd68afa8c7affected
LinuxLinux351df4b201157351c7d26bf12c3eeb9dbce98854 < 89479a27fa4e1e11f378b3724944eabceb84f114affected
LinuxLinux351df4b201157351c7d26bf12c3eeb9dbce98854 < aa807064473abd6f2cafe419fb77ea402d3e3104affected
LinuxLinux351df4b201157351c7d26bf12c3eeb9dbce98854 < 8b4468ec023d0d1b4669dfb867588997cc03a06baffected
LinuxLinux3.8affected
LinuxLinux0 < 3.8unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.96 <= 6.12.*unaffected
LinuxLinux6.18.39 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2-rc1 <= *unaffected

Weaknesses

References