{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.10-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  btrfs: only release the dirty pages io tree after successful writes  [WARNING] With extra warning on dirty extent buffers at umount (aka, the next patch in the series), test case generic/388 can trigger the following warning about dirty extent buffers at unmount time:    BTRFS critical (device dm-2 state E): emergency shutdown   BTRFS error (device dm-2 state E): error while writing out transaction: -30   BTRFS warning (device dm-2 state E): Skipping commit of aborted transaction.   BTRFS error (device dm-2 state EA): Transaction 9 aborted (error -30)   BTRFS: error (device dm-2 state EA) in cleanup_transaction:2068: errno=-30 Readonly filesystem   BTRFS info (device dm-2 state EA): forced readonly   BTRFS info (device dm-2 state EA): last unmount of filesystem 4fbf2e15-f941-49a0-bc7c-716315d2777c   ------------[ cut here ]------------   WARNING: disk-io.c:3311 at invalidate_and_check_btree_folios+0xfd/0x1ca [btrfs], CPU#8: umount/914368   CPU: 8 UID: 0 PID: 914368 Comm: umount Tainted: G           OE       7.1.0-rc1-custom+ #372 PREEMPT(full)  2de38db8d1deae71fde295430a0ff3ab98ccf596   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022   RIP: 0010:invalidate_and_check_btree_folios+0xfd/0x1ca [btrfs]   Call Trace:    \u003cTASK\u003e    close_ctree+0x52e/0x574 [btrfs d2f0b1cd330d1287e7a9919d112eadfc0e914efd]    generic_shutdown_super+0x89/0x1a0    kill_anon_super+0x16/0x40    btrfs_kill_super+0x16/0x20 [btrfs d2f0b1cd330d1287e7a9919d112eadfc0e914efd]    deactivate_locked_super+0x2d/0xb0    cleanup_mnt+0xdc/0x140    task_work_run+0x5a/0xa0    exit_to_user_mode_loop+0x123/0x4b0    do_syscall_64+0x243/0x7c0    entry_SYSCALL_64_after_hwframe+0x4b/0x53    \u003c/TASK\u003e   ---[ end trace 0000000000000000 ]---   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30539776 owner 9 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30621696 owner 257 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30638080 owner 258 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30654464 owner 7 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30703616 owner 2 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30720000 owner 10 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30736384 owner 4 gen 9 refs 2 flags 0x7   BTRFS warning (device dm-2 state EA): unable to release extent buffer 30752768 owner 11 gen 9 refs 2 flags 0x7  I'm using a stripped down version, which seems to trigger the warning more reliably:    _fsstress_pid=\"\"   workload()   {   \tdmesg -C   \tmkfs.btrfs -f -K $dev \u003e /dev/null   \techo 1 \u003e /sys/kernel/debug/clear_warn_once   \tmount $dev $mnt   \t$fsstress -w -n 1024 -p 4 -d $mnt \u0026   \t_fsstress_pid=$!   \tsleep 0   \t$godown $mnt   \tpkill --echo -PIPE fsstress \u003e /dev/null   \twait $_fsstress_pid   \tunset _fsstress_pid   \tumount $mnt    \tif dmesg | grep -q \"WARNING\"; then   \t\tfail   \tfi   }    for (( i = 0; i \u003c $runtime; i++ )); do   \techo \"=== $i/$runtime ===\"   \tworkload   done  [CAUSE] Inside btrfs_write_and_wait_transaction(), we first try to write all dirty ebs, then wait for them to finish.  After that we call btrfs_extent_io_tree_release() to free all extent states from dirty_pages io tree.  However if we hit an error from btrfs_write_marked_extent(), then we still call btrfs_extent_io_tree_release() to clear that dirty_pages io tree, which may contain dirty records that we haven't yet submitted.  Furthermore, the later transaction cleanup path will utilize that dirty_pages io tree to properly cleanup those dirty ebs, but since it's already empty, no dirty ebs are properly cleaned up, thus will later trigger the warnings inside invalidate_btree_folios(). ---truncated---",
  "id": "DEBIAN-CVE-2026-53284",
  "modified": "2026-09-14T16:47:34.314434651Z",
  "published": "2026-06-26T20:17:20.790Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-53284"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-53284"
  ]
}