CVE-2026-23157

CWE-667CWE-8339 documents9 sources
Severity
5.5MEDIUM
EPSS
0.0%
top 99.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateApr 13

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: do not strictly require dirty metadata threshold for metadata writepages [BUG] There is an internal report that over 1000 processes are waiting at the io_schedule_timeout() of balance_dirty_pages(), causing a system hang and trigger a kernel coredump. The kernel is v6.4 kernel based, but the root problem still applies to any upstream kernel before v6.18. [CAUSE] From Jan Kara for his wisdom on the dirty page balance b

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel2.6.296.18.9+1
CVEListV5linux/linux793955bca66c99defdffc857ae6eb7e8431d6bbebb9be3f713652e330df00f3724c18c7a5469e7ac+5
Debianlinux< 6.18.9-1

Patches

🔴Vulnerability Details

4
VulDB
Linux Kernel up to 6.18.8 btrfs io_schedule_timeout deadlock (Nessus ID 299067 / WID-SEC-2026-0421)2026-04-13
CVEList
btrfs: do not strictly require dirty metadata threshold for metadata writepages2026-02-14
OSV
CVE-2026-23157: In the Linux kernel, the following vulnerability has been resolved: btrfs: do not strictly require dirty metadata threshold for metadata writepages [B2026-02-14
GHSA
GHSA-pw2v-cmfh-x2p3: In the Linux kernel, the following vulnerability has been resolved: btrfs: do not strictly require dirty metadata threshold for metadata writepages2026-02-14

📋Vendor Advisories

3
Red Hat
kernel: btrfs: do not strictly require dirty metadata threshold for metadata writepages2026-02-14
Microsoft
btrfs: do not strictly require dirty metadata threshold for metadata writepages2026-02-10
Debian
CVE-2026-23157: linux - In the Linux kernel, the following vulnerability has been resolved: btrfs: do n...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23157 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-23157 (MEDIUM CVSS 5.5) | In the Linux kernel | cvebase.io