Answer in brief
CVE-2026-74365 records a Unknown severity vulnerability in nvdimm/btt: Handle preemption in BTT lane acquisition. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f23859748e3d530217b197e146a9ac84faf0a282 <fd7a97b2514cfc4b4cc067a27dd39bde2a8b1735 || >=6f50b414f1a0d790f11a6438a3ad6d0577eb2c18 <73e35c1bdfa160b41fdbe204e02325f0687de506 || >=36c75ce3bd299878fd9b238e9803d3817ddafbf3 <417918783bcfe0be135019df16a267b3af442efd || >=36c75ce3bd299878fd9b238e9803d3817ddafbf3 <5c53406098b599c420b031e6ec5ba8a2f3794c50 || >=36c75ce3bd299878fd9b238e9803d3817ddafbf3 <4eafa810b042d985ec6bbf5b514414e73cee6f6f || >=36c75ce3bd299878fd9b238e9803d3817ddafbf3 <8d4b989d9c9afe5f185aa5853b666fc4617afe9e || 2577fece583c7c05cda7ad50dde7638c962665e1 || 40ba3fa21250e361bdd8f00800b3e2cb6160de95 || b0e7a935739f33ed2bd6868b89f97dd4c2683c26 || 66eb7b7f23dd9aec5356e7054dd3596ae7648ff5 || b27751fb1f271bbb78d5993c0b10011628e40e18 || >=6.1.63 <6.1.178 || >=6.6.2 <6.6.145 || >=4.19.299 <4.20 || >=5.4.261 <5.5 || >=5.10.201 <5.11 || >=5.15.139 <5.16 || >=6.5.12 <6.6 | fd7a97b2514cfc4b4cc067a27dd39bde2a8b1735, 73e35c1bdfa160b41fdbe204e02325f0687de506, 417918783bcfe0be135019df16a267b3af442efd, 5c53406098b599c420b031e6ec5ba8a2f3794c50, 4eafa810b042d985ec6bbf5b514414e73cee6f6f, 8d4b989d9c9afe5f185aa5853b666fc4617afe9e, 6.1.178, 6.6.145, 4.20, 5.5, 5.11, 5.16, 6.6 |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: Handle preemption in BTT lane acquisition BTT lanes serialize access to per-lane metadata and workspace state during BTT I/O. The btt-check unit test reports data mismatches during BTT writes due to a race in lane acquisition that can lead to silent data corruption. The existing lane model uses a spinlock together with a per-CPU recursion count. That recursion model stopped being valid after BTT lanes became preemptible: another task can run on the same CPU, observe a non-zero recursion count, bypass locking, and use the same lane concurrently. BTT lanes are also held across arena_write_bytes() calls. That path reaches nsio_rw_bytes(), which flushes writes with nvdimm_flush(). Some provider flush callbacks can sleep, making a spinlock the wrong primitive for the lane lifetime. Replace the spinlock-based recursion model with a dynamically allocated per-lane mutex array and take the lane lock unconditionally. Add might_sleep() to catch any future atomic-context caller. Found with the ndctl unit test btt-check.sh.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-74365 records a Unknown severity vulnerability in nvdimm/btt: Handle preemption in BTT lane acquisition. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f23859748e3d530217b197e146a9ac84faf0a282 <fd7a97b2514cfc4b4cc067a27dd39bde2a8b1735 || >=6f50b414f1a0d790f11a6438a3ad6d0577eb2c18 <73e35c1bdfa160b41fdbe204e02325f0687de506 || >=36c75ce3bd299878fd9b238e9803d3817ddafbf3 <417918783bcfe0be135019df16a267b3af442efd || >=36c75ce3bd299878fd9b238e9803d3817ddafbf3 <5c53406098b599c420b031e6ec5ba8a2f3794c50 || >=36c75ce3bd299878fd9b238e9803d3817ddafbf3 <4eafa810b042d985ec6bbf5b514414e73cee6f6f || >=36c75ce3bd299878fd9b238e9803d3817ddafbf3 <8d4b989d9c9afe5f185aa5853b666fc4617afe9e || 2577fece583c7c05cda7ad50dde7638c962665e1 || 40ba3fa21250e361bdd8f00800b3e2cb6160de95 || b0e7a935739f33ed2bd6868b89f97dd4c2683c26 || 66eb7b7f23dd9aec5356e7054dd3596ae7648ff5 || b27751fb1f271bbb78d5993c0b10011628e40e18 || >=6.1.63 <6.1.178 || >=6.6.2 <6.6.145 || >=4.19.299 <4.20 || >=5.4.261 <5.5 || >=5.10.201 <5.11 || >=5.15.139 <5.16 || >=6.5.12 <6.6 | fd7a97b2514cfc4b4cc067a27dd39bde2a8b1735, 73e35c1bdfa160b41fdbe204e02325f0687de506, 417918783bcfe0be135019df16a267b3af442efd, 5c53406098b599c420b031e6ec5ba8a2f3794c50, 4eafa810b042d985ec6bbf5b514414e73cee6f6f, 8d4b989d9c9afe5f185aa5853b666fc4617afe9e, 6.1.178, 6.6.145, 4.20, 5.5, 5.11, 5.16, 6.6 |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 15, 2026
In the Linux kernel, the following vulnerability has been resolved: nvdimm/btt: Handle preemption in BTT lane acquisition BTT lanes serialize access to per-lane metadata and workspace state during BTT I/O. The btt-check unit test reports data mismatches during BTT writes due to a race in lane acquisition that can lead to silent data corruption. The existing lane model uses a spinlock together with a per-CPU recursion count. That recursion model stopped being valid after BTT lanes became preemptible: another task can run on the same CPU, observe a non-zero recursion count, bypass locking, and use the same lane concurrently. BTT lanes are also held across arena_write_bytes() calls. That path reaches nsio_rw_bytes(), which flushes writes with nvdimm_flush(). Some provider flush callbacks can sleep, making a spinlock the wrong primitive for the lane lifetime. Replace the spinlock-based recursion model with a dynamically allocated per-lane mutex array and take the lane lock unconditionally. Add might_sleep() to catch any future atomic-context caller. Found with the ndctl unit test btt-check.sh.
Quoted source text, attributed separately from HOL analysis.