« Volver al listado

CVE-2026-98079

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

btrfs: zstd: fix lost wakeup when waiting for a workspace

A writer can sleep forever in zstd_get_workspace() even though a workspace is free. When zstd_alloc_workspace() fails, the task is queued on zwsm->wait and schedules unconditionally, never re-testing the pool. zstd_put_workspace() publishes the workspace and then calls cond_wake_up(), which only wakes when a sleeper is already visible, so a workspace returned between the failed allocation and prepare_to_wait() wakes nobody. The window is wide: zstd_alloc_workspace() goes through kvmalloc() and may enter reclaim.

Leer descripción completaMostrar menos

Only a max level workspace triggers the wakeup and one is deliberately kept allocated as the fallback every waiter waits for, so once its wakeup is lost the writer stays in TASK_UNINTERRUPTIBLE until some other task happens to return one. Re-check the pool after prepare_to_wait() has published the waiter, and use the workspace if one turned up.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98079",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3f93aef535c8ea03e40cd8acf0753b3e6ed33e96",
              "lessThan": "d8f57049521948df5f50797141472fbbed3b0723",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f93aef535c8ea03e40cd8acf0753b3e6ed33e96",
              "lessThan": "0de9f31d447ae71ab08c7850a321682f8d2907c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3f93aef535c8ea03e40cd8acf0753b3e6ed33e96",
              "lessThan": "2acb9f3d1cc8f65dc81ed55e238cbf8e5b60bff7",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/btrfs/zstd.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/btrfs/zstd.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:37.307",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0de9f31d447ae71ab08c7850a321682f8d2907c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2acb9f3d1cc8f65dc81ed55e238cbf8e5b60bff7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d8f57049521948df5f50797141472fbbed3b0723",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zstd: fix lost wakeup when waiting for a workspace\n\nA writer can sleep forever in zstd_get_workspace() even though a workspace\nis free.  When zstd_alloc_workspace() fails, the task is queued on\nzwsm->wait and schedules unconditionally, never re-testing the pool.\nzstd_put_workspace() publishes the workspace and then calls cond_wake_up(),\nwhich only wakes when a sleeper is already visible, so a workspace returned\nbetween the failed allocation and prepare_to_wait() wakes nobody.  The\nwindow is wide: zstd_alloc_workspace() goes through kvmalloc() and may\nenter reclaim.\n\nOnly a max level workspace triggers the wakeup and one is deliberately kept\nallocated as the fallback every waiter waits for, so once its wakeup is\nlost the writer stays in TASK_UNINTERRUPTIBLE until some other task happens\nto return one.  Re-check the pool after prepare_to_wait() has published the\nwaiter, and use the workspace if one turned up."
    }
  ],
  "lastModified": "2026-09-30T14:10:59.253",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}