CVE-2026-31666 (GCVE-0-2026-31666)
Vulnerability from cvelistv5
Published
2026-04-24 14:45
Modified
2026-08-05 12:24
Summary
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() After commit 1618aa3c2e01 ("btrfs: simplify return variables in lookup_extent_data_ref()"), the err and ret variables were merged into a single ret variable. However, when btrfs_next_leaf() returns 0 (success), ret is overwritten from -ENOENT to 0. If the first key in the next leaf does not match (different objectid or type), the function returns 0 instead of -ENOENT, making the caller believe the lookup succeeded when it did not. This can lead to operations on the wrong extent tree item, potentially causing extent tree corruption. Fix this by returning -ENOENT directly when the key does not match, instead of relying on the ret variable.
Impacted products
Vendor Product Version
Linux Linux Version: 1618aa3c2e0163f5ac34d514ae89474521910536
Version: 1618aa3c2e0163f5ac34d514ae89474521910536
Version: 1618aa3c2e0163f5ac34d514ae89474521910536
Version: 1618aa3c2e0163f5ac34d514ae89474521910536
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "fs/btrfs/extent-tree.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "4125a194db4a6cf91f619f38788272651cb97dce",
              "status": "affected",
              "version": "1618aa3c2e0163f5ac34d514ae89474521910536",
              "versionType": "git"
            },
            {
              "lessThan": "450e6a685d0cad95b15f8af152057bd0bf79f50b",
              "status": "affected",
              "version": "1618aa3c2e0163f5ac34d514ae89474521910536",
              "versionType": "git"
            },
            {
              "lessThan": "ab1e022379c3c811aa72da8eb0c7507859a1d0f5",
              "status": "affected",
              "version": "1618aa3c2e0163f5ac34d514ae89474521910536",
              "versionType": "git"
            },
            {
              "lessThan": "316fb1b3169efb081d2db910cbbfef445afa03b9",
              "status": "affected",
              "version": "1618aa3c2e0163f5ac34d514ae89474521910536",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "fs/btrfs/extent-tree.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.10"
            },
            {
              "lessThan": "6.10",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.82",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.23",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.82",
                  "versionStartIncluding": "6.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.23",
                  "versionStartIncluding": "6.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.13",
                  "versionStartIncluding": "6.10",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "6.10",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref()\n\nAfter commit 1618aa3c2e01 (\"btrfs: simplify return variables in\nlookup_extent_data_ref()\"), the err and ret variables were merged into\na single ret variable. However, when btrfs_next_leaf() returns 0\n(success), ret is overwritten from -ENOENT to 0. If the first key in\nthe next leaf does not match (different objectid or type), the function\nreturns 0 instead of -ENOENT, making the caller believe the lookup\nsucceeded when it did not. This can lead to operations on the wrong\nextent tree item, potentially causing extent tree corruption.\n\nFix this by returning -ENOENT directly when the key does not match,\ninstead of relying on the ret variable."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerable Btrfs extent-reference code is reached through local filesystem syscalls such as reflink/dedupe, truncate, unlink, and hole punching on a writable mounted Btrfs filesystem.\nAC:L - The trigger depends on attacker-shaped filesystem metadata and ordinary repeated file operations, not on a race or condition outside attacker control; when uncertain, the lower-complexity value is appropriate.\nPR:L - A basic unprivileged local user with write access to files on the Btrfs mount can exercise the relevant paths; no real root or init-namespace capability is required.\nUI:N - No separate victim action is required after the attacker has local access to a writable Btrfs filesystem; the attacker can issue the file operations directly.\nS:U - The impact remains within the local kernel/filesystem security authority and does not cross a VM, IOMMU, or similar security boundary.\nC:H - Incorrectly deleting or decrementing the wrong extent data reference can corrupt Btrfs extent ownership, plausibly causing stale or unrelated file data exposure through block reuse or aliasing.\nI:H - The bug can operate on the wrong extent tree item and corrupt filesystem metadata, plausibly enabling corruption or loss of arbitrary file data beyond the attacker\u0027s own intended files.\nA:H - The corrupted extent tree path can trigger transaction aborts, read-only remounts, BUG_ON/oops conditions, or persistent filesystem corruption, causing high availability impact."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:24:16.096Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/4125a194db4a6cf91f619f38788272651cb97dce"
        },
        {
          "url": "https://git.kernel.org/stable/c/450e6a685d0cad95b15f8af152057bd0bf79f50b"
        },
        {
          "url": "https://git.kernel.org/stable/c/ab1e022379c3c811aa72da8eb0c7507859a1d0f5"
        },
        {
          "url": "https://git.kernel.org/stable/c/316fb1b3169efb081d2db910cbbfef445afa03b9"
        }
      ],
      "title": "btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-31666",
    "datePublished": "2026-04-24T14:45:15.271Z",
    "dateReserved": "2026-03-09T15:48:24.129Z",
    "dateUpdated": "2026-08-05T12:24:16.096Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…