CVE-2026-68459
Last modified
CVE-2026-68459 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() When we mount device w/ gc_merge mount option, we may suffer below potential deadlock: Kworker GC trehad Truncator - f2fs_write_cache_pages - f2fs_write_single_data_page - f2fs_do_write_data_page - folio_start_writeback --- set writeback flag on folio - f2fs_outplace_write_data : cached folio in internal bio cache - f2fs_balance_fs - wake_up(gc_thread) : wake up gc thread to run foreground GC - finish_wait(fggc_wq) : wait on the waitqueue --- wait on GC thread to finish the work - truncate_inode_pages_range - __filemap_get_folio(, FGP_LOCK) --- lock folio - truncate_inode_partial_folio - folio_wait_writeback --- wait on writeback being cleared - do_garbage_collect - move_data_page - f2fs_get_lock_data_folio - lock on folio --- blocked on folio's lock In order to avoid such deadlock, let's call below functions to commit cached bios in GC_MERGE path of f2fs_balance_fs() as the same as we did in NOGC_MERGE path. - f2fs_submit_merged_write(sbi, DATA); - f2fs_submit_all_merged_ipu_writes(sbi);. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix potential deadlock in gc_merge path of f2fs_balance_fs() When we mount device w/ gc_merge mount option, we may suffer below potential deadlock: Kworker GC trehad Truncator - f2fs_write_cache_pages - f2fs_write_single_data_page - f2fs_do_write_data_page - folio_start_writeback --- set writeback flag on folio - f2fs_outplace_write_data : cached folio in internal bio cache - f2fs_balance_fs - wake_up(gc_thread) : wake up gc thread to run foreground GC - finish_wait(fggc_wq) : wait on the waitqueue --- wait on GC thread to finish the work - truncate_inode_pages_range - __filemap_get_folio(, FGP_LOCK) --- lock folio - truncate_inode_partial_folio - folio_wait_writeback --- wait on writeback being cleared - do_garbage_collect - move_data_page - f2fs_get_lock_data_folio - lock on folio --- blocked on folio's lock In order to avoid such deadlock, let's call below functions to commit cached bios in GC_MERGE path of f2fs_balance_fs() as the same as we did in NOGC_MERGE path. - f2fs_submit_merged_write(sbi, DATA); - f2fs_submit_all_merged_ipu_writes(sbi);
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 351df4b201157351c7d26bf12c3eeb9dbce98854, < 8071500a8124e5a6d47d901a8d5ffd91743107a1; >= 351df4b201157351c7d26bf12c3eeb9dbce98854, < eb02f218aacb36365e0ca2339cbae81fb05d31a5; >= 351df4b201157351c7d26bf12c3eeb9dbce98854, < 1436031b33fa23ab1ce7df5bc5500093413e8acf; >= 351df4b201157351c7d26bf12c3eeb9dbce98854, < b885c7783c19c36c7bf899492a0bffcd68afa8c7; >= 351df4b201157351c7d26bf12c3eeb9dbce98854, < 89479a27fa4e1e11f378b3724944eabceb84f114; >= 351df4b201157351c7d26bf12c3eeb9dbce98854, < aa807064473abd6f2cafe419fb77ea402d3e3104; >= 351df4b201157351c7d26bf12c3eeb9dbce98854, < 8b4468ec023d0d1b4669dfb867588997cc03a06b |
| Linux | Linux | 3.8 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-68459?
How severe is CVE-2026-68459?
How do I fix CVE-2026-68459?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68453In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2026-68454In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-68455In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68456In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68457In the Linux kernel, the following vulnerability has been re…9.1
- CVE-2026-68458In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-6846A flaw was found in binutils. A heap-buffer-overflow vulnera…7.8
- CVE-2026-68460In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68461In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-68462In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-68463In the Linux kernel, the following vulnerability has been re…
- CVE-2026-68464In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-68459?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
