CVE-2026-64164
Last modified
CVE-2026-64164 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() The trace event btrfs_sync_file() is called in an atomic context (all trace events are) and its call to dput(), which is needed due to the call to dget_parent(), can sleep, triggering a kernel splat. This can be reproduced by enabling the trace event and running btrfs/056 from fstests for example. The splat shown in dmesg is the following: [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970 [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io [53.988] preempt_count: 2, expected: 0 [53.967] RCU nest depth: 0, expected: 0 [53.943] Preemption disabled at: [53.944] [<0000000000000000>] 0x0 [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G W 7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full) [54.070] Tainted: [W]=WARN [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014 [54.072] Call Trace: [54.074] <TASK> [54.076] dump_stack_lvl+0x56/0x80 [54.079] __might_resched.cold+0xd6/0x10f [54.072] dput.part.0+0x24/0x110 [54.078] trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs] [54.089] btrfs_sync_file+0x1ed/0x530 [btrfs] [54.087] ? __handle_mm_fault+0x8ae/0xed0 [54.089] btrfs_do_write_iter+0x172/0x210 [btrfs] [54.091] vfs_write+0x21f/0x450 [54.094] __x64_sys_pwrite64+0x8d/0xc0 [54.096] ? do_user_addr_fault+0x20c/0x670 [54.099] do_syscall_64+0x60/0xf20 [54.092] ? clear_bhb_loop+0x60/0xb0 [54.094] entry_SYSCALL_64_after_hwframe+0x76/0x7e So stop using dget_parent() and dput() and access the parent dentry directly as dentry->d_parent. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() The trace event btrfs_sync_file() is called in an atomic context (all trace events are) and its call to dput(), which is needed due to the call to dget_parent(), can sleep, triggering a kernel splat. This can be reproduced by enabling the trace event and running btrfs/056 from fstests for example. The splat shown in dmesg is the following: [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970 [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io [53.988] preempt_count: 2, expected: 0 [53.967] RCU nest depth: 0, expected: 0 [53.943] Preemption disabled at: [53.944] [<0000000000000000>] 0x0 [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G W 7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full) [54.070] Tainted: [W]=WARN [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014 [54.072] Call Trace: [54.074] <TASK> [54.076] dump_stack_lvl+0x56/0x80 [54.079] __might_resched.cold+0xd6/0x10f [54.072] dput.part.0+0x24/0x110 [54.078] trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs] [54.089] btrfs_sync_file+0x1ed/0x530 [btrfs] [54.087] ? __handle_mm_fault+0x8ae/0xed0 [54.089] btrfs_do_write_iter+0x172/0x210 [btrfs] [54.091] vfs_write+0x21f/0x450 [54.094] __x64_sys_pwrite64+0x8d/0xc0 [54.096] ? do_user_addr_fault+0x20c/0x670 [54.099] do_syscall_64+0x60/0xf20 [54.092] ? clear_bhb_loop+0x60/0xb0 [54.094] entry_SYSCALL_64_after_hwframe+0x76/0x7e So stop using dget_parent() and dput() and access the parent dentry directly as dentry->d_parent. This is also what ext4 is doing in its equivalent trace event ext4_sync_file_enter().
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 4a7bab35fad5251c8cb738161152578cd83b6b9c, < d78b0a80eac36879ef5478707135c446920e134b; >= 520e8b4bcf872a534a7bf61ccf880047642df296, < 4361954f0e158af0530caa1e57f12b531be4658f; >= e252db8ca2a01f82d472091f35d549b313278636, < 6279992c9ba2774901c9d4dd4a481162e2534714; >= c09a7446aab5773f38d6abb25fce99b8e1dfbc97, < 26b2290baaf6da6add0f782a100766e686a33f4f; >= 32372781d664a9b03c40343e96c29d0a6139f97d, < 12a0487945c09760a5968d9333383014ea294117; >= 2e4adfaec97ee053ad1bdfb5036845e66f7e0d8a, < c32a7e0e3c73c1c0768556a56bd78de9f7b83780; >= a85b46db143fda5869e7d8df8f258ccef5fa1719, < 0a96d9a85cd2240481297156b9bb72e10b7a8036; >= a85b46db143fda5869e7d8df8f258ccef5fa1719, < c73370c677646e86fc4b1780fb07027bdf847375; d110d7cdb045715c0b45b0dfd974525bb38f653d; >= 6.6.136, < 6.6.142; >= 6.12.83, < 6.12.92; >= 6.18.24, < 6.18.34; >= 6.19.14, < 6.20 |
| Linux | Linux | 7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-64164?
How severe is CVE-2026-64164?
How do I fix CVE-2026-64164?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-64159In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6416Tanium addressed an uncontrolled resource consumption vulner…4.9
- CVE-2026-64160In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64161In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64162In the Linux kernel, the following vulnerability has been re…9.8
- CVE-2026-64163In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64165In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64166In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64167In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64168In the Linux kernel, the following vulnerability has been re…
- CVE-2026-64169In the Linux kernel, the following vulnerability has been re…
- CVE-2026-6417The GLS Shipping for WooCommerce plugin for WordPress is vul…6.1
Are you affected by CVE-2026-64164?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
