PT-2026-98742 · Linux · Linux
CVE-2026-98079
·
Published
2026-09-25
·
Updated
2026-09-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
btrfs: zstd: fix lost wakeup when waiting for a workspace
A writer can sleep forever in zstd get workspace() even though a workspace
is free. When zstd alloc workspace() fails, the task is queued on
zwsm->wait and schedules unconditionally, never re-testing the pool.
zstd put workspace() publishes the workspace and then calls cond wake up(),
which only wakes when a sleeper is already visible, so a workspace returned
between the failed allocation and prepare to wait() wakes nobody. The
window is wide: zstd alloc workspace() goes through kvmalloc() and may
enter reclaim.
Only a max level workspace triggers the wakeup and one is deliberately kept
allocated as the fallback every waiter waits for, so once its wakeup is
lost the writer stays in TASK UNINTERRUPTIBLE until some other task happens
to return one. Re-check the pool after prepare to wait() has published the
waiter, and use the workspace if one turned up.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux