CVE-2026-64164
Received Received - Intake

Sleep-in-atomic-context in Linux Kernel Btrfs

Vulnerability report for CVE-2026-64164, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-19

Last updated on: 2026-07-19

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() The trace event btrfs_sync_file() is called in an atomic context (all trace events are) and its call to dput(), which is needed due to the call to dget_parent(), can sleep, triggering a kernel splat. This can be reproduced by enabling the trace event and running btrfs/056 from fstests for example. The splat shown in dmesg is the following: [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970 [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io [53.988] preempt_count: 2, expected: 0 [53.967] RCU nest depth: 0, expected: 0 [53.943] Preemption disabled at: [53.944] [<0000000000000000>] 0x0 [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G W 7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full) [54.070] Tainted: [W]=WARN [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014 [54.072] Call Trace: [54.074] <TASK> [54.076] dump_stack_lvl+0x56/0x80 [54.079] __might_resched.cold+0xd6/0x10f [54.072] dput.part.0+0x24/0x110 [54.078] trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs] [54.089] btrfs_sync_file+0x1ed/0x530 [btrfs] [54.087] ? __handle_mm_fault+0x8ae/0xed0 [54.089] btrfs_do_write_iter+0x172/0x210 [btrfs] [54.091] vfs_write+0x21f/0x450 [54.094] __x64_sys_pwrite64+0x8d/0xc0 [54.096] ? do_user_addr_fault+0x20c/0x670 [54.099] do_syscall_64+0x60/0xf20 [54.092] ? clear_bhb_loop+0x60/0xb0 [54.094] entry_SYSCALL_64_after_hwframe+0x76/0x7e So stop using dget_parent() and dput() and access the parent dentry directly as dentry->d_parent. This is also what ext4 is doing in its equivalent trace event ext4_sync_file_enter().

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-19
Last Modified
2026-07-19
Generated
2026-07-20
AI Q&A
2026-07-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel 7.1.0-rc1-btrfs-next-232+

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability in the Btrfs filesystem. The issue occurs in the trace event btrfs_sync_file() which runs in an atomic context where sleeping is not allowed. The function calls dput() via dget_parent(), which can sleep and trigger a kernel warning or crash. The fix avoids this by directly accessing the parent dentry instead of using dget_parent() and dput().

Detection Guidance

This vulnerability can be detected by enabling the btrfs_sync_file trace event and running btrfs/056 from fstests. Check dmesg for kernel splats indicating sleeping in atomic context. The error will show a BUG message with sleeping function called from invalid context at fs/dcache.c.

Impact Analysis

This vulnerability can cause kernel warnings or crashes when the Btrfs trace event is enabled and certain filesystem operations are performed. It may lead to system instability or unexpected behavior during file operations on Btrfs filesystems.

Compliance Impact

This vulnerability is a kernel-level issue in the Linux filesystem (btrfs) that causes a kernel splat due to sleeping in an atomic context. It does not directly impact data privacy, security controls, or compliance with standards like GDPR or HIPAA, as it is a system stability issue rather than a data exposure or access control flaw.

Mitigation Strategies

Apply the kernel patch that removes dget_parent() and dput() calls in btrfs_sync_file() and accesses the parent dentry directly via dentry->d_parent. This aligns with the fix used in ext4's equivalent trace event.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64164. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart