In the Linux kernel, the following vulnerability has been resolved:
gfs2: Prevent recursive memory reclaim
Function new_inode() returns a new inode with inode->i_mapping->gfp_mask set to GFP_HIGHUSER_MOVABLE. This value includes the __GFP_FS flag, so allocations in that address space can recurse into filesystem memory reclaim. We don't want that to happen because it can consume a significant amount of stack memory.
Worse than that is that it can also deadlock: for example, in several places, gfs2_unstuff_dinode() is called inside filesystem transactions. This calls filemap_grab_folio(), which can allocate a new folio, which can trigger memory reclaim. If memory reclaim recurses into the filesystem and starts another transaction, a deadlock will ensue.
To fix these kinds of problems, prevent memory reclaim from recursing into filesystem code by making sure that the gfp_mask of inode address spaces doesn't include __GFP_FS.
The "meta" and resource group address spaces were already using GFP_NOFS as their gfp_mask (which doesn't include __GFP_FS). The default value of GFP_HIGHUSER_MOVABLE is less restrictive than GFP_NOFS, though. To avoid being overly limiting, use the default value and only knock off the __GFP_FS flag. I'm not sure if this will actually make a difference, but it also shouldn't hurt.
This patch is loosely based on commit ad22c7a043c2 ("xfs: prevent stack overflows from page cache allocation").
Fixes xfstest generic/273.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Oracle_linux | — | Upgrade kernel-uek | Feb 24, 2026 | Dec 24, 2025 |
| Ubuntu | — | Upgrade linux-image-azure-6.17Upgrade linux-image-6.17.0-19-generic-64kUpgrade linux-image-genericUpgrade linux-image-6.17.0-19-genericUpgrade linux-image-generic-6.17Upgrade linux-image-azureUpgrade linux-image-generic-64k-6.17Upgrade linux-image-gcp-64k-6.17Upgrade linux-image-virtual-6.17Upgrade linux-image-aws-64kUpgrade linux-image-6.17.0-1009-oracleUpgrade linux-image-oem-24.04Upgrade linux-image-raspiUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oem-24.04bUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-aws-6.17Upgrade linux-image-6.17.0-1017-oemUpgrade linux-image-generic-64kUpgrade linux-image-6.17.0-1010-azureUpgrade linux-image-gcp-64kUpgrade linux-image-6.17.0-1009-awsUpgrade linux-image-oracle-64kUpgrade linux-image-oracle-6.17Upgrade linux-image-6.17.0-1009-oracle-64kUpgrade linux-image-realtimeUpgrade linux-image-aws-64k-6.17Upgrade linux-image-6.17.0-1010-raspiUpgrade linux-image-virtualUpgrade linux-image-oem-6.17Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.17.0-1008-realtimeUpgrade linux-image-6.17.0-1009-gcpUpgrade linux-image-oracle-64k-6.17Upgrade linux-image-oem-24.04dUpgrade linux-image-oem-24.04aUpgrade linux-image-gcpUpgrade linux-image-6.17.0-1009-gcp-64kUpgrade linux-image-oracleUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-oem-24.04cUpgrade linux-image-gcp-6.17Upgrade linux-image-awsUpgrade linux-image-raspi-6.17Upgrade linux-image-6.17.0-1009-aws-64kUpgrade linux-image-realtime-6.17 | Mar 17, 2026 | Dec 24, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Sep 15, 2026 | Dec 24, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub