Linux kernel CVE announcements
 help / color / mirror / Atom feed
* CVE-2026-89646: ceph: fix leaked inode reference on writeback abort at umount
@ 2026-09-11 19:45 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-11 19:45 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

ceph: fix leaked inode reference on writeback abort at umount

ceph_dirty_folio() takes a wrbuffer claim on each newly dirtied folio: it
bumps i_wrbuffer_ref (taking an ihold() on the 0->1 transition) and
attaches the snap_context to folio->private.  That claim is released only
by ceph_put_wrbuffer_cap_refs(), which for a submitted write runs from
writepages_finish().

In ceph_submit_write(), if ceph_inc_osd_stopping_blocker() fails -- which
happens during umount -- the request is aborted before submission: the
already-collected folios are only redirtied and unlocked, so
writepages_finish() never runs and the claim is leaked.
redirty_page_for_writepage() -> folio_redirty_for_writepage() ->
filemap_dirty_folio() sets PG_dirty directly and does not go through
->dirty_folio, so ceph_dirty_folio() is not re-entered to rebalance it.
Because every subsequent writeback also fails the osd_stopping_blocker,
i_wrbuffer_ref never returns to 0, the ihold() is never dropped, and the
inode cannot be evicted:

  VFS: Busy inodes after unmount of ceph
  kernel BUG at fs/super.c:650!

Release the orphaned claim in the abort path before redirtying, via
ceph_undo_wrbuffer_claim(): detach the snap_context, drop the wrbuffer
reference (letting i_wrbuffer_ref reach 0 and iput() the inode), and drop
the snap_context reference -- i.e. do what writepages_finish() would have
done for these never-submitted folios.

Only the locked_pages entries are undone; folios still in the fbatch were
never dirty-cleared by this call (folio_clear_dirty_for_io() is the
ownership-transfer point, and a successful move NULLs the fbatch slot), so
they hold no claim this call owns.

The Linux kernel CVE team has assigned CVE-2026-89646 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.15 with commit fd7449d937e7fb3144770592927cf452bf66dbd3 and fixed in 6.18.50 with commit ec32015a955c5d326c5e26610edfdcccd52f2314
	Issue introduced in 6.15 with commit fd7449d937e7fb3144770592927cf452bf66dbd3 and fixed in 7.2.4 with commit ac7a5a5385762df458d10cccc086a4e079be7409
	Issue introduced in 6.15 with commit fd7449d937e7fb3144770592927cf452bf66dbd3 and fixed in 7.3-rc1 with commit c25aee9c630fb86f98d79eccb75765067079b972

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-89646
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	fs/ceph/addr.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/ec32015a955c5d326c5e26610edfdcccd52f2314
	https://git.kernel.org/stable/c/ac7a5a5385762df458d10cccc086a4e079be7409
	https://git.kernel.org/stable/c/c25aee9c630fb86f98d79eccb75765067079b972

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-11 20:00 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-11 19:45 CVE-2026-89646: ceph: fix leaked inode reference on writeback abort at umount Greg Kroah-Hartman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox