CVE-2026-80528: ceph: avoid fs reclaim while using current->journal_info
In the Linux kernel, the following vulnerability has been resolved:
ceph: avoid fs reclaim while using current->journalinfo
handlereply() stores a cephmdsrequest pointer in current->journalinfo while filling the inode and dentry cache from an MDS reply.
An allocation in this section can enter direct reclaim and prune dentries from another filesystem. If this dirties an ext4 inode, ext4 starts a JBD2 transaction. JBD2 interprets the Ceph request in current->journalinfo as a journal handle and dereferences the request's rtid as htransaction, causing a kernel crash, e.g.:
Unable to handle kernel paging request at virtual address 00000000077b4818 [...] Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G W 6.18.38-i3 #1113 NONE [...] Workqueue: ceph-msgr cephconworkfn pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : jbd2journalstart+0x2c/0x208 lr : ext4journalstartsb+0x100/0x178 [...] Call trace: jbd2journalstart+0x2c/0x208 (P) ext4journalstartsb+0x100/0x178 ext4dirtyinode+0x3c/0x90 markinodedirty+0x58/0x400 iput.part.0+0x2b0/0x370 iput+0x18/0x30 dentryunlinkinode+0xc0/0x158 dentrykill+0x80/0x250 shrinkdentrylist+0x90/0x130 prunedcachesb+0x60/0x98 supercachescan+0xe8/0x190 doshrinkslab+0x174/0x388 shrinkslab+0xd8/0x4c0 shrinknode+0x31c/0x908 dotrytofreepages+0xd0/0x508 trytofreepages+0x11c/0x238 allocfrozenpagesnoprof+0x4d0/0xdd0 folioallocnoprof+0x18/0x70 filemapgetfolio+0x248/0x440 cephreaddirprepopulate+0x570/0x9e8 mdsdispatch+0x1424/0x1ba0 cephconprocessmessage+0x74/0xa0 cephconv1tryread+0x3a0/0x1510 cephconworkfn+0x260/0x460
Enter a scoped NOFS allocation context and leave it after clearing journalinfo. This prevents filesystem reclaim from recursing into another filesystem while the field contains Ceph-private data.