{"id":"CVE-2026-74572","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-74572","summary":"btrfs: zoned: fix deadlock between metadata writeback and transaction commit","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: fix deadlock between metadata writeback and transaction commit\n\nWhen writing out metadata extent buffers in a zoned filesystem,\nbtree_writepages() holds fs_info->zoned_meta_io_lock across the whole\nwriteback loop, including the call to btrfs_check_meta_write_pointer() ->\ncheck_bg_is_active().\n\nFor the tree-log block group, check_bg_is_active() may fail to activate\nthe zone and fall back to btrfs_zone_finish_one_bg() to free an active\nzone. That path waits for the running transaction to commit while still\nholding zoned_meta_io_lock, but the committer needs that same lock to\nwrite out the tree extents, so the two tasks deadlock:\n\n  Task A (kworker, metadata writeback)      Task B (fsstress, transaction commit)\n  ------------------------------------      -------------------------------------\n  wb_workfn()                               btrfs_commit_transaction(T)\n   btree_writepages()                        btrfs_write_and_wait_transaction()\n    btrfs_zoned_meta_io_lock()                btrfs_write_marked_extents()\n    btrfs_check_meta_write_pointer()           btree_writepages()\n     check_bg_is_active() [treelog_bg]          btrfs_zoned_meta_io_lock()\n      btrfs_zone_finish_one_bg()               <blocks on zoned_meta_io_lock,\n       btrfs_zone_finish()                      held by Task A>\n        do_zone_finish()\n         btrfs_inc_block_group_ro()\n          btrfs_wait_for_commit()\n           <blocks waiting for commit\n            of transaction T, done by\n            Task B>\n\nThe sibling branch in check_bg_is_active() already drops zoned_meta_io_lock\naround do_zone_finish() for this exact reason. Do the same in the tree-log\nbranch: release the lock around btrfs_zone_finish_one_bg() and re-acquire\nit afterwards. The lock only protects fs_info->active_{meta,system}_bg,\nwhich this branch does not touch, and ctx->zoned_bg keeps a reference to\nthe block group across the unlock, so nothing is lost while the lock\nis dropped.\n\nThis hang occasionally reproduces with fstests generic/475 on a zoned\nbtrfs filesystem.","published":"2026-08-15T12:28:11.328Z","modified":"2026-08-18T03:56:51.842184130Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Linux","name":"Kernel","fixedVersion":"6.6.151"}],"fix":null,"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/18577e77c2c8adaadf1f7c6e9bcd1c0b14e5dcdd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/1ebe51c29fa9755d5b2fea28727c051117907cf8"},{"type":"WEB","url":"https://git.kernel.org/stable/c/75859a7cd77cd2ddaddbcb963e3fcd34738953af"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c3320873e0c04ce7b746fc8fe948f07bbbbdec33"},{"type":"WEB","url":"https://git.kernel.org/stable/c/deddd28fd83c264ee2ff5cd6b34449a9f1be6112"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74572.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74572"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T03:56:51.842184130Z"}}