{"api_version":"1","generated_at":"2026-07-20T14:43:00+00:00","cve":"CVE-2026-64164","urls":{"html":"https://cve.report/CVE-2026-64164","api":"https://cve.report/api/cve/CVE-2026-64164.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64164","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64164"},"summary":{"title":"btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()\n\nThe trace event btrfs_sync_file() is called in an atomic context (all trace\nevents are) and its call to dput(), which is needed due to the call to\ndget_parent(), can sleep, triggering a kernel splat.\n\nThis can be reproduced by enabling the trace event and running btrfs/056\nfrom fstests for example. The splat shown in dmesg is the following:\n\n  [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970\n  [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io\n  [53.988] preempt_count: 2, expected: 0\n  [53.967] RCU nest depth: 0, expected: 0\n  [53.943] Preemption disabled at:\n  [53.944] [<0000000000000000>] 0x0\n  [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G        W           7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full)\n  [54.070] Tainted: [W]=WARN\n  [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014\n  [54.072] Call Trace:\n  [54.074]  <TASK>\n  [54.076]  dump_stack_lvl+0x56/0x80\n  [54.079]  __might_resched.cold+0xd6/0x10f\n  [54.072]  dput.part.0+0x24/0x110\n  [54.078]  trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs]\n  [54.089]  btrfs_sync_file+0x1ed/0x530 [btrfs]\n  [54.087]  ? __handle_mm_fault+0x8ae/0xed0\n  [54.089]  btrfs_do_write_iter+0x172/0x210 [btrfs]\n  [54.091]  vfs_write+0x21f/0x450\n  [54.094]  __x64_sys_pwrite64+0x8d/0xc0\n  [54.096]  ? do_user_addr_fault+0x20c/0x670\n  [54.099]  do_syscall_64+0x60/0xf20\n  [54.092]  ? clear_bhb_loop+0x60/0xb0\n  [54.094]  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nSo stop using dget_parent() and dput() and access the parent dentry\ndirectly as dentry->d_parent. This is also what ext4 is doing in\nits equivalent trace event ext4_sync_file_enter().","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-19 16:17:58","updated_at":"2026-07-19 16:17:58"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/12a0487945c09760a5968d9333383014ea294117","name":"https://git.kernel.org/stable/c/12a0487945c09760a5968d9333383014ea294117","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c32a7e0e3c73c1c0768556a56bd78de9f7b83780","name":"https://git.kernel.org/stable/c/c32a7e0e3c73c1c0768556a56bd78de9f7b83780","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c73370c677646e86fc4b1780fb07027bdf847375","name":"https://git.kernel.org/stable/c/c73370c677646e86fc4b1780fb07027bdf847375","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d78b0a80eac36879ef5478707135c446920e134b","name":"https://git.kernel.org/stable/c/d78b0a80eac36879ef5478707135c446920e134b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/26b2290baaf6da6add0f782a100766e686a33f4f","name":"https://git.kernel.org/stable/c/26b2290baaf6da6add0f782a100766e686a33f4f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4361954f0e158af0530caa1e57f12b531be4658f","name":"https://git.kernel.org/stable/c/4361954f0e158af0530caa1e57f12b531be4658f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0a96d9a85cd2240481297156b9bb72e10b7a8036","name":"https://git.kernel.org/stable/c/0a96d9a85cd2240481297156b9bb72e10b7a8036","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/6279992c9ba2774901c9d4dd4a481162e2534714","name":"https://git.kernel.org/stable/c/6279992c9ba2774901c9d4dd4a481162e2534714","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64164","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64164","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4a7bab35fad5251c8cb738161152578cd83b6b9c d78b0a80eac36879ef5478707135c446920e134b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 520e8b4bcf872a534a7bf61ccf880047642df296 4361954f0e158af0530caa1e57f12b531be4658f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e252db8ca2a01f82d472091f35d549b313278636 6279992c9ba2774901c9d4dd4a481162e2534714 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected c09a7446aab5773f38d6abb25fce99b8e1dfbc97 26b2290baaf6da6add0f782a100766e686a33f4f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 32372781d664a9b03c40343e96c29d0a6139f97d 12a0487945c09760a5968d9333383014ea294117 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2e4adfaec97ee053ad1bdfb5036845e66f7e0d8a c32a7e0e3c73c1c0768556a56bd78de9f7b83780 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a85b46db143fda5869e7d8df8f258ccef5fa1719 0a96d9a85cd2240481297156b9bb72e10b7a8036 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a85b46db143fda5869e7d8df8f258ccef5fa1719 c73370c677646e86fc4b1780fb07027bdf847375 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d110d7cdb045715c0b45b0dfd974525bb38f653d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.6.136 6.6.142 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.12.83 6.12.92 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.18.24 6.18.34 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.19.14 6.20 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.0","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.142 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.92 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.34 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0.11 7.0.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["include/trace/events/btrfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"d78b0a80eac36879ef5478707135c446920e134b","status":"affected","version":"4a7bab35fad5251c8cb738161152578cd83b6b9c","versionType":"git"},{"lessThan":"4361954f0e158af0530caa1e57f12b531be4658f","status":"affected","version":"520e8b4bcf872a534a7bf61ccf880047642df296","versionType":"git"},{"lessThan":"6279992c9ba2774901c9d4dd4a481162e2534714","status":"affected","version":"e252db8ca2a01f82d472091f35d549b313278636","versionType":"git"},{"lessThan":"26b2290baaf6da6add0f782a100766e686a33f4f","status":"affected","version":"c09a7446aab5773f38d6abb25fce99b8e1dfbc97","versionType":"git"},{"lessThan":"12a0487945c09760a5968d9333383014ea294117","status":"affected","version":"32372781d664a9b03c40343e96c29d0a6139f97d","versionType":"git"},{"lessThan":"c32a7e0e3c73c1c0768556a56bd78de9f7b83780","status":"affected","version":"2e4adfaec97ee053ad1bdfb5036845e66f7e0d8a","versionType":"git"},{"lessThan":"0a96d9a85cd2240481297156b9bb72e10b7a8036","status":"affected","version":"a85b46db143fda5869e7d8df8f258ccef5fa1719","versionType":"git"},{"lessThan":"c73370c677646e86fc4b1780fb07027bdf847375","status":"affected","version":"a85b46db143fda5869e7d8df8f258ccef5fa1719","versionType":"git"},{"status":"affected","version":"d110d7cdb045715c0b45b0dfd974525bb38f653d","versionType":"git"},{"lessThan":"6.6.142","status":"affected","version":"6.6.136","versionType":"semver"},{"lessThan":"6.12.92","status":"affected","version":"6.12.83","versionType":"semver"},{"lessThan":"6.18.34","status":"affected","version":"6.18.24","versionType":"semver"},{"lessThan":"6.20","status":"affected","version":"6.19.14","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["include/trace/events/btrfs.h"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.0"},{"lessThan":"7.0","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.142","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.92","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.34","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.11","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.142","versionStartIncluding":"6.6.136","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.92","versionStartIncluding":"6.12.83","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.34","versionStartIncluding":"6.18.24","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.11","versionStartIncluding":"7.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"7.0","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.19.14","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()\n\nThe trace event btrfs_sync_file() is called in an atomic context (all trace\nevents are) and its call to dput(), which is needed due to the call to\ndget_parent(), can sleep, triggering a kernel splat.\n\nThis can be reproduced by enabling the trace event and running btrfs/056\nfrom fstests for example. The splat shown in dmesg is the following:\n\n  [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970\n  [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io\n  [53.988] preempt_count: 2, expected: 0\n  [53.967] RCU nest depth: 0, expected: 0\n  [53.943] Preemption disabled at:\n  [53.944] [<0000000000000000>] 0x0\n  [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G        W           7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full)\n  [54.070] Tainted: [W]=WARN\n  [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014\n  [54.072] Call Trace:\n  [54.074]  <TASK>\n  [54.076]  dump_stack_lvl+0x56/0x80\n  [54.079]  __might_resched.cold+0xd6/0x10f\n  [54.072]  dput.part.0+0x24/0x110\n  [54.078]  trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs]\n  [54.089]  btrfs_sync_file+0x1ed/0x530 [btrfs]\n  [54.087]  ? __handle_mm_fault+0x8ae/0xed0\n  [54.089]  btrfs_do_write_iter+0x172/0x210 [btrfs]\n  [54.091]  vfs_write+0x21f/0x450\n  [54.094]  __x64_sys_pwrite64+0x8d/0xc0\n  [54.096]  ? do_user_addr_fault+0x20c/0x670\n  [54.099]  do_syscall_64+0x60/0xf20\n  [54.092]  ? clear_bhb_loop+0x60/0xb0\n  [54.094]  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nSo stop using dget_parent() and dput() and access the parent dentry\ndirectly as dentry->d_parent. This is also what ext4 is doing in\nits equivalent trace event ext4_sync_file_enter()."}],"providerMetadata":{"dateUpdated":"2026-07-19T15:40:49.894Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/d78b0a80eac36879ef5478707135c446920e134b"},{"url":"https://git.kernel.org/stable/c/4361954f0e158af0530caa1e57f12b531be4658f"},{"url":"https://git.kernel.org/stable/c/6279992c9ba2774901c9d4dd4a481162e2534714"},{"url":"https://git.kernel.org/stable/c/26b2290baaf6da6add0f782a100766e686a33f4f"},{"url":"https://git.kernel.org/stable/c/12a0487945c09760a5968d9333383014ea294117"},{"url":"https://git.kernel.org/stable/c/c32a7e0e3c73c1c0768556a56bd78de9f7b83780"},{"url":"https://git.kernel.org/stable/c/0a96d9a85cd2240481297156b9bb72e10b7a8036"},{"url":"https://git.kernel.org/stable/c/c73370c677646e86fc4b1780fb07027bdf847375"}],"title":"btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64164","datePublished":"2026-07-19T15:40:49.894Z","dateReserved":"2026-07-19T07:54:57.038Z","dateUpdated":"2026-07-19T15:40:49.894Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-19 16:17:58","lastModifiedDate":"2026-07-19 16:17:58","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64164","Ordinal":"1","Title":"btrfs: tracepoints: fix sleep while in atomic context in btrfs_s","CVE":"CVE-2026-64164","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64164","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()\n\nThe trace event btrfs_sync_file() is called in an atomic context (all trace\nevents are) and its call to dput(), which is needed due to the call to\ndget_parent(), can sleep, triggering a kernel splat.\n\nThis can be reproduced by enabling the trace event and running btrfs/056\nfrom fstests for example. The splat shown in dmesg is the following:\n\n  [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970\n  [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io\n  [53.988] preempt_count: 2, expected: 0\n  [53.967] RCU nest depth: 0, expected: 0\n  [53.943] Preemption disabled at:\n  [53.944] [<0000000000000000>] 0x0\n  [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G        W           7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full)\n  [54.070] Tainted: [W]=WARN\n  [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014\n  [54.072] Call Trace:\n  [54.074]  <TASK>\n  [54.076]  dump_stack_lvl+0x56/0x80\n  [54.079]  __might_resched.cold+0xd6/0x10f\n  [54.072]  dput.part.0+0x24/0x110\n  [54.078]  trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs]\n  [54.089]  btrfs_sync_file+0x1ed/0x530 [btrfs]\n  [54.087]  ? __handle_mm_fault+0x8ae/0xed0\n  [54.089]  btrfs_do_write_iter+0x172/0x210 [btrfs]\n  [54.091]  vfs_write+0x21f/0x450\n  [54.094]  __x64_sys_pwrite64+0x8d/0xc0\n  [54.096]  ? do_user_addr_fault+0x20c/0x670\n  [54.099]  do_syscall_64+0x60/0xf20\n  [54.092]  ? clear_bhb_loop+0x60/0xb0\n  [54.094]  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nSo stop using dget_parent() and dput() and access the parent dentry\ndirectly as dentry->d_parent. This is also what ext4 is doing in\nits equivalent trace event ext4_sync_file_enter().","Type":"Description","Title":"btrfs: tracepoints: fix sleep while in atomic context in btrfs_s"}]}}}