CVE-2023-52668: btrfs: zoned: fix lock ordering in btrfs_zone_activate()

Published May 17, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

btrfs: zoned: fix lock ordering in btrfszoneactivate()

The btrfs CI reported a lockdep warning as follows by running generic generic/129.

WARNING: possible circular locking dependency detected 6.7.0-rc5+ #1 Not tainted ------------------------------------------------------ kworker/u5:5/793427 is trying to acquire lock: ffff88813256d028 (&cache->lock){+.+.}-{2:2}, at: btrfszonefinishonebg+0x5e/0x130 but task is already holding lock: ffff88810a23a318 (&fsinfo->zoneactivebgslock){+.+.}-{2:2}, at: btrfszonefinishonebg+0x34/0x130 which lock already depends on the new lock.

the existing dependency chain (in reverse order) is: -> #1 (&fsinfo->zoneactivebgslock){+.+.}-{2:2}: ... -> #0 (&cache->lock){+.+.}-{2:2}: ...

This is because we take fsinfo->zoneactivebgslock after a blockgroup's lock in btrfszoneactivate() while doing the opposite in other places.

Fix the issue by expanding the fsinfo->zoneactivebgslock's critical section and taking it before a blockgroup's lock.

Affected Software

4 affected components
Linux Kernel>=6.7.0-rc5
Linux Linux kernel>=6.6<6.6.15
Linux Linux kernel>=6.7<6.7.3
Linux Linux kernel=6.8-rc1

Event History

May 17, 2024
CVE Published
via MITRE·02:01 PM
Data Sourced
via MITRE·02:01 PM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2023-52668?

CVE-2023-52668 has not been assigned a specific severity rating, but it addresses a potential circular locking dependency in the Linux kernel.

2

How do I fix CVE-2023-52668?

To resolve CVE-2023-52668, users should update their Linux kernel to a version that includes the fix for the vulnerability.

3

Is CVE-2023-52668 exploitable?

CVE-2023-52668 primarily involves a locking issue which could lead to stability problems but is not categorized as a direct exploit.

4

Which versions of the Linux kernel are affected by CVE-2023-52668?

CVE-2023-52668 affects versions of the Linux kernel starting from 6.7.0-rc5.

5

What components of the Linux kernel does CVE-2023-52668 involve?

CVE-2023-52668 involves the btrfs file system and its lock ordering mechanism.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203