PT-2026-8152 · Linux+1 · Linux Kernel+1

Jan Kara

·

Published

2026-01-01

·

Updated

2026-05-26

·

CVE-2026-23157

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.18
Description The Linux kernel contains a flaw in the btrfs subsystem related to dirty metadata page handling. Specifically, the kernel may strictly require a dirty metadata threshold for metadata writepages, potentially leading to a deadlock situation. This can occur when a cgroup has a limited memory allocation and a task dirties more pages than the cgroup's dirty limit. The btrfs internal threshold for writeback can exceed the cgroup's dirty limit, preventing writeback and causing processes to hang while waiting to reduce the number of dirty pages. This issue affects kernels before version 6.18, but newer kernels utilizing AS KERNEL FILE may not be impacted. The issue can cause a system hang and kernel coredump, with reports indicating over 1000 processes waiting at the io schedule timeout() function.
Recommendations versions prior to 6.18: Update to version 6.18 or later to address the issue.

Exploit

Fix

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-77820
CVE-2026-23157
ECHO-9888-52BC-B81F
OPENSUSE-SU-2026:20416-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1041-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21114-1
SUSE-SU-2026:21123-1
SUSE-SU-2026:21255-1
SUSE-SU-2026:21284-1

Affected Products

Linux Kernel
Btrfs