Executive brief
A deadlock condition exists in the Linux kernel's btrfs filesystem when using the flushoncommit mount option and cloning inline extents with non-zero destination offsets. This causes system processes to hang indefinitely, resulting in service unavailability and potential data loss if the filesystem becomes unresponsive during critical operations.
Technical details
The vulnerability is a deadlock triggered during the reflink operation (file cloning) when copying inline extent data to a destination with a non-zero offset on btrfs filesystems mounted with flushoncommit. The root cause is incomplete locking logic: a prior fix (commit b48c980b6a7e) addressed the deadlock only for destination offset 0, but missed the case where offset > 0. The issue occurs between extent locking in the writeback path and transaction commit locking. An attacker with local filesystem access (requiring write permissions) can trigger this via reflink syscalls, causing indefinite blocking of writeback and transaction threads. The fix ensures proper i_size updates whenever inline extent data is cloned, preventing the deadlock condition. Patches are expected in subsequent kernel releases.
Affected products
- Linux Linux kernel 5.x through 6.x (btrfs subsystem)
Timeline
- 2026-08-15: disclosed