Skip to content
Noroxi
CVE-2025-71065· NVD / CVE Program· CNA Linux

f2fs: fix to avoid potential deadlock

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid potential deadlock As Jiaming Zhang and syzbot reported, there is potential deadlock in f2fs as below: Chain exists of: &sbi->cp_rwsem --> fs_reclaim --> sb_internal#2 Possible unsafe locking scenario: CPU0 CPU1 ---- ---- rlock(sb_internal#2); lock(fs_reclaim); lock(sb_internal#2); rlock(&sbi->cp_rwsem); *** DEADLOCK *** 3 locks held by kswapd0/73: #0: ffffffff8e247a40 (fs_reclaim){+.+.}-{0:0}, at: balance_pgdat mm/vmscan.c:7015 [inline] #0: ffffffff8e247a40 (fs_reclaim){+.+.}-{0:0}, at: kswapd+0x951/0x2800 mm/vmscan.c:7389 #1: ffff8880118400e0 (&type->s_umount_key#50){.+.+}-{4:4}, at: super_trylock_shared fs/super.c:562 [inline] #1: ffff8880118400e0 (&type->s_umount_key#50){.+.+}-{4:4}, at: super_cache_scan+0x91/0x4b0 fs/super.c:197 #2: ffff888011840610 (sb_internal#2){.+.+}-{0:0}, at: f2fs_evict_inode+0x8d9/0x1b60 fs/f2fs/inode.c:890 stack backtrace: CPU: 0 UID: 0 PID: 73 Comm: kswapd0 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120 print_circular_bug+0x2ee/0x310 kernel/locking/lockdep.c:2043 check_noncircular+0x134/0x160 kernel/locking/lockdep.c:2175 check_prev_add kernel/locking/lockdep.c:3165 [inline] check_prevs_add kernel/locking/lockdep.c:3284 [inline] validate_chain+0xb9b/0x2140 kernel/locking/lockdep.c:3908 __lock_acquire+0xab9/0xd20 kernel/locking/lockdep.c:5237 lock_acquire+0x120/0x360 kernel/locking/lockdep.c:5868 down_read+0x46/0x2e0 kernel/locking/rwsem.c:1537 f2fs_down_read fs/f2fs/f2fs.h:2278 [inline] f2fs_lock_op fs/f2fs/f2fs.h:2357 [inline] f2fs_do_truncate_blocks+0x21c/0x10c0 fs/f2fs/file.c:791 f2fs_truncate_blocks+0x10a/0x300 fs/f2fs/file.c:867 f2fs_truncate+0x489/0x7c0 fs/f2fs/file.c:925 f2fs_evict_inode+0x9f2/0x1b60 fs/f2fs/inode.c:897 evict+0x504/0x9c0 fs/inode.c:810 f2fs_evict_inode+0x1dc/0x1b60 fs/f2fs/inode.c:853 evict+0x504/0x9c0 fs/inode.c:810 dispose_list fs/inode.c:852 [inline] prune_icache_sb+0x21b/0x2c0 fs/inode.c:1000 super_cache_scan+0x39b/0x4b0 fs/super.c:224 do_shrink_slab+0x6ef/0x1110 mm/shrinker.c:437 shrink_slab_memcg mm/shrinker.c:550 [inline] shrink_slab+0x7ef/0x10d0 mm/shrinker.c:628 shrink_one+0x28a/0x7c0 mm/vmscan.c:4955 shrink_many mm/vmscan.c:5016 [inline] lru_gen_shrink_node mm/vmscan.c:5094 [inline] shrink_node+0x315d/0x3780 mm/vmscan.c:6081 kswapd_shrink_node mm/vmscan.c:6941 [inline] balance_pgdat mm/vmscan.c:7124 [inline] kswapd+0x147c/0x2800 mm/vmscan.c:7389 kthread+0x70e/0x8a0 kernel/kthread.c:463 ret_from_fork+0x4bc/0x870 arch/x86/kernel/process.c:158 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245 </TASK> The root cause is deadlock among four locks as below: kswapd - fs_reclaim --- Lock A - shrink_one - evict - f2fs_evict_inode - sb_start_intwrite --- Lock B - iput - evict - f2fs_evict_inode - sb_start_intwrite --- Lock B - f2fs_truncate - f2fs_truncate_blocks - f2fs_do_truncate_blocks - f2fs_lock_op --- Lock C ioctl - f2fs_ioc_commit_atomic_write - f2fs_lock_op --- Lock C - __f2fs_commit_atomic_write - __replace_atomic_write_block - f2fs_get_dnode_of_data - __get_node_folio - f2fs_check_nid_range - f2fs_handle_error - f2fs_record_errors - f2fs_down_write --- Lock D open - do_open - do_truncate - security_inode_need_killpriv - f2fs_getxattr - lookup_all_xattrs - f2fs_handle_error - f2fs_record_errors - f2fs_down_write --- Lock D - f2fs_commit_super - read_mapping_folio - filemap_alloc_folio_noprof - prepare_alloc_pages - fs_reclaim_acquire --- Lock A In order to a ---truncated---

—No exploit Fix available
Published
Jan 13, 2026
Updated
Jun 17, 2026
EPSS
0.2% · 8th percentile
CWE
—
Follow this CVE

Sign in to follow · You’ll be notified if a followed record enters KEV, gets an exploit or is updated.

Report tools

JSON

Action score

0

Monitor

Low priority for now.

CVSS
0 / 40 · —
CISA KEV
0 / 30 · Not listed
EPSS
0 / 30 · 0.2%

Affected systems

—

Versions reported by the vendor

Affected version ranges reported by the assigning authority (Linux). Independent of NVD's CPE analysis and usually ahead of it.

  • Linux Linux

    • 6.1affected
    • 95fa90c9e5a7f14c2497d5b032544478c9377c3a and later · before 8bd6dff8b801abaa362272894bda795bf0cf1307affected · git
    • 95fa90c9e5a7f14c2497d5b032544478c9377c3a and later · before 6c3bab5c6261aa22c561ef56b7365959a90e7d91affected · git
    • 95fa90c9e5a7f14c2497d5b032544478c9377c3a and later · before 86a85a7b622e6e8dba69810257733ce5eab5ed55affected · git
    • 95fa90c9e5a7f14c2497d5b032544478c9377c3a and later · before ca8b201f28547e28343a6f00a6e91fa8c09572feaffected · git
    • before 6.1not affected · semver
    • 6.6.120 and later · up to and including 6.6.*not affected · semver
    • 6.12.64 and later · up to and including 6.12.*not affected · semver
    • 6.18.3 and later · up to and including 6.18.*not affected · semver
    • 6.19 and laternot affected · original_commit_for_fix

Package-level exposure

OSV and GitHub Advisory data: ecosystem, package and range. SBOM matching uses this table.

EcosystemPackageAffected rangeFix
Debian:12linuxall versions—
Debian:13linuxbefore 6.12.69-16.12.69-1
Debian:14linuxbefore 6.18.3-16.18.3-1

Other highest-scoring records for the same primary product.

  • CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation
    40Plan
  • CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment
    40Plan
  • CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()
    40Plan
  • CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
    40Plan
  • CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
    40Plan
  • CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index
    40Plan

Remediation

Which version to upgrade to

Fix versions compiled from the vendor, package registries and Microsoft. Verify the vendor's note before upgrading.

Product / packageFixed versionSource
Linux Linux6c3bab5c6261aa22c561ef56b7365959a90e7d91Vendor (CNA)
Linux Linux86a85a7b622e6e8dba69810257733ce5eab5ed55Vendor (CNA)
Linux Linux8bd6dff8b801abaa362272894bda795bf0cf1307Vendor (CNA)
Linux Linuxca8b201f28547e28343a6f00a6e91fa8c09572feVendor (CNA)
azl3 kernel 6.6.119.3-3 on Azure Linux 3.06.6.121.1-1 · CBL-Mariner ReleasesMicrosoft (MSRC)
debian:linux6.12.69-1 · Debian:13Package registry (OSV)

Exploit status

No known public exploit

No public exploit has been observed yet. That doesn't mean you're safe, only that the bar is a little higher.

Research context

For pentesters and researchers: attack profile, score disagreement, timeline, patch commits, credits, variant and chain candidates, bug bounty scope. All derived from existing data; no exploit code.

Timeline

From publication to today: proof of concept, Metasploit module, CISA KEV and fix record. Dates are as reported by the sources.

No dated events beyond publication.

EPSS, last 120 days

FIRST EPSS daily score; only changes of 0.01 or more are recorded (step chart).

Patch and commit links

Commit, PR and diff links among the references. A starting point for patch-diffing and variant hunting; fixes, not exploits.

No commit or PR link among the references.

Finders, reporters and analysts named in the CNA record. Click a name for that researcher’s other records.

No credits in the CNA record.

Variant candidates

Same product, same weakness class, within 18 months. If the patch missed the root cause, the sibling bug is here.

No nightly-computed relations.

Chain candidates

An authentication bypass and a privilege-requiring bug in the same product, published close together: combined they may become an unauthenticated path.

—

Bug bounty scope

No known public program.

Source: bounty-targets-data (public HackerOne, Bugcrowd, Intigriti, YesWeHack listings).

Technical details

No CVSS vector for this record, so attack conditions can't be derived.

Weakness class (CWE)

—

Attack context

MITRE CAPEC attack patterns and ATT&CK techniques for this weakness class (CWE). A starting point for detection rules and threat hunting.

MITRE has no CAPEC/ATT&CK mapping for this CWE.

Noroxi analysis

No Noroxi analysis for this record yet

We don't hand-write analysis for all 385,000+ vulnerabilities; that wouldn't be honest. For notable, high-impact vulnerabilities our team writes the mechanism, detection and remediation steps.

We use this product, ask for help

Change log

  1. Fix✗ → ✓

For records you follow, these changes also arrive as notifications. →

References

All records