{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()  The trace event btrfs_sync_file() is called in an atomic context (all trace events are) and its call to dput(), which is needed due to the call to dget_parent(), can sleep, triggering a kernel splat.  This can be reproduced by enabling the trace event and running btrfs/056 from fstests for example. The splat shown in dmesg is the following:    [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970   [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io   [53.988] preempt_count: 2, expected: 0   [53.967] RCU nest depth: 0, expected: 0   [53.943] Preemption disabled at:   [53.944] [\u003c0000000000000000\u003e] 0x0   [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G        W           7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full)   [54.070] Tainted: [W]=WARN   [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014   [54.072] Call Trace:   [54.074]  \u003cTASK\u003e   [54.076]  dump_stack_lvl+0x56/0x80   [54.079]  __might_resched.cold+0xd6/0x10f   [54.072]  dput.part.0+0x24/0x110   [54.078]  trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs]   [54.089]  btrfs_sync_file+0x1ed/0x530 [btrfs]   [54.087]  ? __handle_mm_fault+0x8ae/0xed0   [54.089]  btrfs_do_write_iter+0x172/0x210 [btrfs]   [54.091]  vfs_write+0x21f/0x450   [54.094]  __x64_sys_pwrite64+0x8d/0xc0   [54.096]  ? do_user_addr_fault+0x20c/0x670   [54.099]  do_syscall_64+0x60/0xf20   [54.092]  ? clear_bhb_loop+0x60/0xb0   [54.094]  entry_SYSCALL_64_after_hwframe+0x76/0x7e  So stop using dget_parent() and dput() and access the parent dentry directly as dentry-\u003ed_parent. This is also what ext4 is doing in its equivalent trace event ext4_sync_file_enter().",
  "id": "DEBIAN-CVE-2026-64164",
  "modified": "2026-09-14T16:47:28.945993212Z",
  "published": "2026-07-19T16:17:58.450Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64164"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64164"
  ]
}