GHSA-phqv-2q9m-94vvunknown
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential deadlock...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs()
When we mount device w/ gc_merge mount option, we may suffer below potential deadlock:
Kworker GC trehad Truncator
- f2fs_write_cache_pages
- f2fs_write_single_data_page
- f2fs_do_write_data_page
- folio_start_writeback --- set writeback flag on folio
- f2fs_outplace_write_data : cached folio in internal bio cache
- f2fs_balance_fs
- wake_up(gc_thread) : wake up gc thread to run foreground GC
- finish_wait(fggc_wq) : wait on the waitqueue --- wait on GC thread to finish the work - truncate_inode_pages_range - __filemap_get_folio(, FGP_LOCK) --- lock folio - truncate_inode_partial_folio - folio_wait_writeback --- wait on writeback being cleared - do_garbage_collect - move_data_page - f2fs_get_lock_data_folio - lock on folio --- blocked on folio's lock
In order to avoid such deadlock, let's call below functions to commit cached bios in GC_MERGE path of f2fs_balance_fs() as the same as we did in NOGC_MERGE path.
- f2fs_submit_merged_write(sbi, DATA);
- f2fs_submit_all_merged_ipu_writes(sbi);
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-68459
- https://git.kernel.org/stable/c/1436031b33fa23ab1ce7df5bc5500093413e8acf
- https://git.kernel.org/stable/c/8071500a8124e5a6d47d901a8d5ffd91743107a1
- https://git.kernel.org/stable/c/89479a27fa4e1e11f378b3724944eabceb84f114
- https://git.kernel.org/stable/c/8b4468ec023d0d1b4669dfb867588997cc03a06b
- https://git.kernel.org/stable/c/aa807064473abd6f2cafe419fb77ea402d3e3104
- https://git.kernel.org/stable/c/b885c7783c19c36c7bf899492a0bffcd68afa8c7
- https://git.kernel.org/stable/c/eb02f218aacb36365e0ca2339cbae81fb05d31a5
- https://github.com/advisories/GHSA-phqv-2q9m-94vv