Skip to main content
EPSS 0.2%top 91%

In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: fix deadlock waiting for ticket during data relocation When… (CVE-2026-74319)

0
Medium
Published: 08/15/2026 (08/15/2026, 06:32:29 UTC)
Source: GCVE Database

Description

A deadlock vulnerability in the Linux kernel's BTRFS zoned filesystem data relocation process has been resolved. The issue occurs when the relocation process waits indefinitely for a space reservation ticket that cannot be fulfilled because the relocation itself is responsible for freeing the space. The fix introduces a new flush state to avoid re-entering the relocation code and breaking the deadlock cycle.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 16:09:43 UTC

Technical Analysis

CVE-2026-74319 addresses a deadlock in the Linux kernel's BTRFS zoned filesystem during data relocation. Specifically, the handle_reserve_tickets() function can deadlock because the relocation process waits on a space reservation ticket that cannot be fulfilled, as the relocation is the operation that frees the required space. The resolution involves adding a new flush state, BTRFS_RESERVE_FLUSH_ZONED_RELOCATION, which uses priority_reclaim_data_space() instead of the normal flushing path. This prevents re-entry into the relocation code and thus breaks the deadlock cycle. The allocation function btrfs_alloc_data_chunk_ondemand() was updated to select this new flush state when the inode belongs to a data relocation root on a zoned filesystem.

Potential Impact

The vulnerability can cause a deadlock during data relocation on a zoned BTRFS filesystem, potentially leading to system hangs or unresponsiveness related to filesystem operations. There is no indication of data corruption or privilege escalation from the provided information.

Mitigation Recommendations

A fix has been implemented in the Linux kernel to address this deadlock by introducing a new flush state that prevents the deadlock cycle. Users should apply the official kernel updates that include this fix. Since no patch links or vendor advisories are provided, check the Linux kernel release notes or vendor advisories for the specific patch and update accordingly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-w48h-wv4w-hrq6
Osv Schema Version
1.4.0
Aliases
["CVE-2026-74319"]

Threat ID: 6a808b6abf8831d5394f6fbb

Added to database: 08/15/2026, 15:53:14 UTC

Last enriched: 08/15/2026, 16:09:43 UTC

Last updated: 09/30/2026, 06:54:41 UTC

Views: 55

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses