Junglewise Threat Intelligence

CVE-2026-23157: Linux Kernel Btrfs deadlock in metadata writepages

CVE-2026-23157 · Severity: medium · CVSS 5.5 · Published 2026-02-14

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Btrfs file system can cause a complete system hang. This occurs when the system's memory management and the file system enter a deadlock state while trying to manage data being written to the disk, particularly in environments with restricted memory limits like containers (cgroups). An exploit of this flaw results in a denial of service, requiring a system reboot and potentially causing operational downtime.

Technical details

A deadlock exists in the Btrfs file system between the btree inode writeback process and the cgroup dirty page throttling mechanism. Btrfs historically used an internal 32MiB threshold before triggering metadata writeback via btree_writepages(). In environments where a cgroup has a memory limit lower than this threshold (e.g., 16MiB), the memory management subsystem will throttle processes once the limit is reached, waiting for writeback to free memory. However, Btrfs will not initiate writeback because its internal threshold has not been met, resulting in a circular dependency and system hang. The fix involves removing the strict internal threshold in btree_writepages() to respect external writeback requests. This affects kernels prior to v6.18.

Affected products

  • Linux Linux Kernel from 2.6.29 up to 6.18.9

Timeline

  • 2026-02-14: advisory: CVE published
  • 2026-03-25: patched: Fixes merged into various stable branches

References

Related threats