Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97689.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-97689
Upstream
Published
2026-08-26T15:17:06Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-80528 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

ceph: avoid fs reclaim while using current->journal_info

handle_reply() stores a ceph_mds_request pointer in current->journal_info while filling the inode and dentry cache from an MDS reply.

An allocation in this section can enter direct reclaim and prune dentries from another filesystem. If this dirties an ext4 inode, ext4 starts a JBD2 transaction. JBD2 interprets the Ceph request in current->journal_info as a journal handle and dereferences the request's r_tid as h_transaction, causing a kernel crash, e.g.:

Unable to handle kernel paging request at virtual address 00000000077b4818 [...] Internal error: Oops: 0000000096000004 [#1] SMP Modules linked in: CPU: 6 UID: 0 PID: 2699135 Comm: kworker/6:3 Tainted: G W 6.18.38-i3 #1113 NONE [...] Workqueue: ceph-msgr cephconworkfn pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : jbd2__journal_start+0x2c/0x208 lr : ext4journalstart_sb+0x100/0x178 [...] Call trace: jbd2journal_start+0x2c/0x208 (P) __ext4journalstart_sb+0x100/0x178 ext4dirtyinode+0x3c/0x90 __markinodedirty+0x58/0x400 iput.part.0+0x2b0/0x370 iput+0x18/0x30 dentryunlinkinode+0xc0/0x158 __dentrykill+0x80/0x250 shrinkdentrylist+0x90/0x130 prunedcachesb+0x60/0x98 supercachescan+0xe8/0x190 doshrinkslab+0x174/0x388 shrinkslab+0xd8/0x4c0 shrinknode+0x31c/0x908 dotrytofreepages+0xd0/0x508 trytofreepages+0x11c/0x238 __allocfrozenpages_noprof+0x4d0/0xdd0 __folioallocnoprof+0x18/0x70 __filemapgetfolio+0x248/0x440 cephreaddirprepopulate+0x570/0x9e8 mdsdispatch+0x1424/0x1ba0 cephconprocessmessage+0x74/0xa0 cephconv1tryread+0x3a0/0x1510 cephconworkfn+0x260/0x460

Enter a scoped NOFS allocation context and leave it after clearing journal_info. This prevents filesystem reclaim from recursing into another filesystem while the field contains Ceph-private data.

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97689.json"