CVE-2025-37856 (GCVE-0-2025-37856)
Vulnerability from cvelistv5
Published
2025-05-09 06:42
Modified
2026-08-05 11:57
Summary
In the Linux kernel, the following vulnerability has been resolved: btrfs: harden block_group::bg_list against list_del() races As far as I can tell, these calls of list_del_init() on bg_list cannot run concurrently with btrfs_mark_bg_unused() or btrfs_mark_bg_to_reclaim(), as they are in transaction error paths and situations where the block group is readonly. However, if there is any chance at all of racing with mark_bg_unused(), or a different future user of bg_list, better to be safe than sorry. Otherwise we risk the following interleaving (bg_list refcount in parens) T1 (some random op) T2 (btrfs_mark_bg_unused) !list_empty(&bg->bg_list); (1) list_del_init(&bg->bg_list); (1) list_move_tail (1) btrfs_put_block_group (0) btrfs_delete_unused_bgs bg = list_first_entry list_del_init(&bg->bg_list); btrfs_put_block_group(bg); (-1) Ultimately, this results in a broken ref count that hits zero one deref early and the real final deref underflows the refcount, resulting in a WARNING.
Impacted products
Vendor Product Version
Linux Linux Version: a9f189716cf15913c453299d72f69c51a9b0f86b
Version: a9f189716cf15913c453299d72f69c51a9b0f86b
Version: a9f189716cf15913c453299d72f69c51a9b0f86b
Version: a9f189716cf15913c453299d72f69c51a9b0f86b
Version: edf3b5aadb2515c808200b904baa5b70a727f0ac
Version: 01eca70ef8cf499d0cb6d1bbd691558e7792cf17
Version: 5d19abcffd8404078dfa7d7118cec357b5e7bc58
Version: 5.15.128   
Version: 6.1.47   
Version: 6.4.12   
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/btrfs/extent-tree.c",
            "fs/btrfs/transaction.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "bf089c4d1141b27332c092b1dcca5022c415a3b6",
              "status": "affected",
              "version": "a9f189716cf15913c453299d72f69c51a9b0f86b",
              "versionType": "git"
            },
            {
              "lessThan": "909e60fb469d4101c6b08cf6e622efb062bb24a1",
              "status": "affected",
              "version": "a9f189716cf15913c453299d72f69c51a9b0f86b",
              "versionType": "git"
            },
            {
              "lessThan": "185fd73e5ac06027c4be9a129e59193f6a3ef202",
              "status": "affected",
              "version": "a9f189716cf15913c453299d72f69c51a9b0f86b",
              "versionType": "git"
            },
            {
              "lessThan": "7511e29cf1355b2c47d0effb39e463119913e2f6",
              "status": "affected",
              "version": "a9f189716cf15913c453299d72f69c51a9b0f86b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "edf3b5aadb2515c808200b904baa5b70a727f0ac",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "01eca70ef8cf499d0cb6d1bbd691558e7792cf17",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5d19abcffd8404078dfa7d7118cec357b5e7bc58",
              "versionType": "git"
            },
            {
              "lessThan": "5.16",
              "status": "affected",
              "version": "5.15.128",
              "versionType": "semver"
            },
            {
              "lessThan": "6.2",
              "status": "affected",
              "version": "6.1.47",
              "versionType": "semver"
            },
            {
              "lessThan": "6.5",
              "status": "affected",
              "version": "6.4.12",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/btrfs/extent-tree.c",
            "fs/btrfs/transaction.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "lessThan": "6.5",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.24",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.13.*",
              "status": "unaffected",
              "version": "6.13.12",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.14.*",
              "status": "unaffected",
              "version": "6.14.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.15",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.24",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13.12",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14.3",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15",
                  "versionStartIncluding": "6.5",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.15.128",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.1.47",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "6.4.12",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: harden block_group::bg_list against list_del() races\n\nAs far as I can tell, these calls of list_del_init() on bg_list cannot\nrun concurrently with btrfs_mark_bg_unused() or btrfs_mark_bg_to_reclaim(),\nas they are in transaction error paths and situations where the block\ngroup is readonly.\n\nHowever, if there is any chance at all of racing with mark_bg_unused(),\nor a different future user of bg_list, better to be safe than sorry.\n\nOtherwise we risk the following interleaving (bg_list refcount in parens)\n\nT1 (some random op)                       T2 (btrfs_mark_bg_unused)\n                                        !list_empty(\u0026bg-\u003ebg_list); (1)\nlist_del_init(\u0026bg-\u003ebg_list); (1)\n                                        list_move_tail (1)\nbtrfs_put_block_group (0)\n                                        btrfs_delete_unused_bgs\n                                             bg = list_first_entry\n                                             list_del_init(\u0026bg-\u003ebg_list);\n                                             btrfs_put_block_group(bg); (-1)\n\nUltimately, this results in a broken ref count that hits zero one deref\nearly and the real final deref underflows the refcount, resulting in a WARNING."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable code is btrfs\u0027s core block-group allocator, reached through ordinary file creation/deletion, `sync()`/`fsync()`, and ENOSPC-driven transaction aborts on a locally mounted btrfs filesystem. There is no network protocol handler in the path.\nAC:L - The attacker drives both sides of the race with a single unprivileged workload \u2014 emptying block groups feeds `btrfs_mark_bg_unused()` while `sync()` forces the `btrfs_finish_extent_commit()` traversal \u2014 and the create/delete/sync loop can be repeated indefinitely until the window is hit. The same bg_list refcount race was demonstrably reproduced in practice by its sibling CVE-2025-22115 and by fstests generic/297.\nPR:L - Any unprivileged local user with write access to a btrfs mount (home directory, `/tmp`, or a container volume) can trigger the full sequence; no capability, no user namespace, and no CAP_SYS_ADMIN operation such as scrub or balance is required.\nUI:N - The attacker\u0027s own process performs every step, and the cleaner kthread consumes the freed object on its own timer. btrfs is the default root filesystem on Fedora and openSUSE, so no victim needs to mount anything.\nS:U - The refcount underflow, the freed object, and its consumer all live in the kernel\u0027s own security authority, with no crossing of a hypervisor, IOMMU, or sandbox boundary.\nC:H - `btrfs_put_block_group()` `kfree()`s the block group into a general kmalloc cache while it is still linked on `fs_info-\u003eunused_bgs`, so an unprivileged heap spray can reclaim the slot and the cleaner kthread will read `space_info`, `start`, `length`, and `flags` back out of it, exposing kernel heap contents.\nI:H - `list_del_init()` on the freed node writes through attacker-reclaimed `prev`/`next` pointers, yielding a controlled kernel write primitive, and the downstream `btrfs_remove_chunk(trans, block_group-\u003estart)` operates on a garbage offset, destroying live on-disk btrfs metadata.\nA:H - The refcount underflow raises `refcount_t: underflow; use-after-free`, an immediate panic under the widely deployed `panic_on_warn=1`, and the use-after-free crashes the cleaner kthread and can corrupt or wedge the filesystem outright."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:57:52.765Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bf089c4d1141b27332c092b1dcca5022c415a3b6"
        },
        {
          "url": "https://git.kernel.org/stable/c/909e60fb469d4101c6b08cf6e622efb062bb24a1"
        },
        {
          "url": "https://git.kernel.org/stable/c/185fd73e5ac06027c4be9a129e59193f6a3ef202"
        },
        {
          "url": "https://git.kernel.org/stable/c/7511e29cf1355b2c47d0effb39e463119913e2f6"
        }
      ],
      "title": "btrfs: harden block_group::bg_list against list_del() races",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-37856",
    "datePublished": "2025-05-09T06:42:04.315Z",
    "dateReserved": "2025-04-16T04:51:23.956Z",
    "dateUpdated": "2026-08-05T11:57:52.765Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…