CVE-2023-52668

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/05/2024
Last modified:
19/09/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> btrfs: zoned: fix lock ordering in btrfs_zone_activate()<br /> <br /> The btrfs CI reported a lockdep warning as follows by running generic<br /> generic/129.<br /> <br /> WARNING: possible circular locking dependency detected<br /> 6.7.0-rc5+ #1 Not tainted<br /> ------------------------------------------------------<br /> kworker/u5:5/793427 is trying to acquire lock:<br /> ffff88813256d028 (&amp;cache-&gt;lock){+.+.}-{2:2}, at: btrfs_zone_finish_one_bg+0x5e/0x130<br /> but task is already holding lock:<br /> ffff88810a23a318 (&amp;fs_info-&gt;zone_active_bgs_lock){+.+.}-{2:2}, at: btrfs_zone_finish_one_bg+0x34/0x130<br /> which lock already depends on the new lock.<br /> <br /> the existing dependency chain (in reverse order) is:<br /> -&gt; #1 (&amp;fs_info-&gt;zone_active_bgs_lock){+.+.}-{2:2}:<br /> ...<br /> -&gt; #0 (&amp;cache-&gt;lock){+.+.}-{2:2}:<br /> ...<br /> <br /> This is because we take fs_info-&gt;zone_active_bgs_lock after a block_group&amp;#39;s<br /> lock in btrfs_zone_activate() while doing the opposite in other places.<br /> <br /> Fix the issue by expanding the fs_info-&gt;zone_active_bgs_lock&amp;#39;s critical<br /> section and taking it before a block_group&amp;#39;s lock.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6 (including) 6.6.15 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.7.3 (excluding)
cpe:2.3:o:linux:linux_kernel:6.8:rc1:*:*:*:*:*:*