Executive brief
The Linux kernel's BTT (Block Translation Table) subsystem, used for managing persistent memory I/O operations, contains a race condition in lane acquisition that can cause silent data corruption during write operations. An attacker or unprivileged user with kernel module loading capabilities or direct hardware access could trigger concurrent access to shared lane metadata, resulting in data corruption and potential system instability. This is a low-risk vulnerability for most systems as it requires specific preemption conditions and BTT hardware usage.
Technical details
This is a synchronization vulnerability (CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization) in the nvdimm/btt lane acquisition logic. The root cause is an invalid recursion model using per-CPU spinlocks and recursion counts that became unsafe after BTT lanes became preemptible—another task running on the same CPU could observe a non-zero recursion count, bypass locking, and access the same lane concurrently. Additionally, lane locks are held across arena_write_bytes() calls that invoke nvdimm_flush(), whose callbacks may sleep, making spinlocks unsuitable. The race leads to data mismatches during BTT write operations. The fix replaces the spinlock-based recursion model with a dynamically allocated per-lane mutex array, taken unconditionally. The vulnerability affects systems using BTT with preemptible kernels; exploitation is local and requires kernel-level access or ability to trigger concurrent I/O patterns. A patch was committed by Alison Schofield in upstream Linux and backported to stable kernels.
Affected products
- Linux Linux kernel Affected versions with BTT preemption support; patched in commit 8d4b989d9c9afe5f185aa5853b666fc4617afe9e
Timeline
- 2026-08-15: disclosed: CVE-2026-74365 published
- 2026-05-27: patched: Upstream fix committed by Alison Schofield
- 2026-07-24: other: Backported to stable kernels by Greg Kroah-Hartman