CVE-2026-74321 (GCVE-0-2026-74321)
Vulnerability from cvelistv5
Published
2026-08-15 05:58
Modified
2026-08-17 05:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
In the beginning of the loop, we try to obtain a locked delayed ref head,
if 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(),
which can return an error pointer. If the error pointer is -EAGAIN we do
a continue and go back to the beginning of the loop, which will not try
again to call btrfs_select_ref_head() since 'locked_ref' is no longer
NULL but it's ERR_PTR(-EAGAIN), and then we do:
spin_lock(&locked_ref->lock);
against a ERR_PTR(-EAGAIN) value, generating an invalid pointer
dereference.
Fix this by ensuring that 'locked_ref' is set to NULL when
btrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count'
as well, to prevent infinite looping. We do this by doing a goto to the
bottom of the loop that already sets 'locked_ref' to NULL and does a
cond_resched(), with an increment to 'count' right before the goto.
These measures were in place before the refactoring in commit 0110a4c43451
("btrfs: refactor __btrfs_run_delayed_refs loop") but were unintentionally
lost afterwards.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 Version: 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/extent-tree.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "c372ca227e16bace86f1df1fa4ae6849e2fcfa28",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "a71143590ce9764dbcb47617647592ff8b4d48bc",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "65770111a2d47c2b15e20b2ba92bb12198f289d4",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "015dc4a1e0c2cba551d4620eba13d26d5081dc34",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "ba9fa2ff5981589bb49094d3358c339b37c47f53",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "9faa6b69ad73f03c7bde53e07d75a28822dc9a1a",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
},
{
"lessThan": "486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae",
"status": "affected",
"version": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/extent-tree.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()\n\nIn the beginning of the loop, we try to obtain a locked delayed ref head,\nif \u0027locked_ref\u0027 is currently NULL, by calling btrfs_select_ref_head(),\nwhich can return an error pointer. If the error pointer is -EAGAIN we do\na continue and go back to the beginning of the loop, which will not try\nagain to call btrfs_select_ref_head() since \u0027locked_ref\u0027 is no longer\nNULL but it\u0027s ERR_PTR(-EAGAIN), and then we do:\n\n spin_lock(\u0026locked_ref-\u003elock);\n\nagainst a ERR_PTR(-EAGAIN) value, generating an invalid pointer\ndereference.\n\nFix this by ensuring that \u0027locked_ref\u0027 is set to NULL when\nbtrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing \u0027count\u0027\nas well, to prevent infinite looping. We do this by doing a goto to the\nbottom of the loop that already sets \u0027locked_ref\u0027 to NULL and does a\ncond_resched(), with an increment to \u0027count\u0027 right before the goto.\nThese measures were in place before the refactoring in commit 0110a4c43451\n(\"btrfs: refactor __btrfs_run_delayed_refs loop\") but were unintentionally\nlost afterwards."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - On storage servers exporting btrfs via nfsd or ksmbd, remote client write/fsync/unlink I/O reaches btrfs_run_delayed_refs() and __btrfs_run_delayed_refs() in the server kernel without any local syscall; this is the highest-impact but reasonable deployment for btrfs metadata processing.\nAC:L - -EAGAIN is returned when a concurrent task deletes the delayed-ref head during btrfs_delayed_ref_lock(); an attacker controls both sides by driving parallel writes/unlinks/fsync or multiple NFS/SMB clients, reliably hitting the documented race without uncontrollable layout or victim state.\nPR:N - Exploitation needs only network write access to an NFS or SMB export of the btrfs filesystem; no local account, Linux capability, or init-namespace privilege is required when the export permits client writes (including anonymous/guest exports common on NAS appliances).\nUI:N - The fault is triggered entirely by the attacker\u0027s own concurrent filesystem I/O against an already-exported btrfs volume; no separate victim must mount a filesystem, open a file, or perform any interactive action beyond the attacker\u0027s own operations.\nS:U - The invalid pointer dereference and resulting kernel oops occur within the host kernel\u0027s btrfs delayed-ref processing; no VM escape, IOMMU bypass, or cross-sandbox boundary is crossed.\nC:N - The bug dereferences ERR_PTR(-EAGAIN), a small negative sentinel address, not freed or attacker-controlled memory; spin_lock faults immediately without returning kernel data, so there is no information-disclosure or read primitive.\nI:N - This is a logic error causing an invalid pointer dereference, not a use-after-free, out-of-bounds write, or type confusion; no kernel memory is modified before the faulting access aborts execution.\nA:H - Dereferencing ERR_PTR(-EAGAIN) in spin_lock(\u0026locked_ref-\u003elock) causes a kernel oops/panic during delayed-ref processing, which can hang or crash the host and deny all service on the affected btrfs filesystem; the condition is repeatable with concurrent I/O."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:45:52.396Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/c372ca227e16bace86f1df1fa4ae6849e2fcfa28"
},
{
"url": "https://git.kernel.org/stable/c/a71143590ce9764dbcb47617647592ff8b4d48bc"
},
{
"url": "https://git.kernel.org/stable/c/65770111a2d47c2b15e20b2ba92bb12198f289d4"
},
{
"url": "https://git.kernel.org/stable/c/015dc4a1e0c2cba551d4620eba13d26d5081dc34"
},
{
"url": "https://git.kernel.org/stable/c/ba9fa2ff5981589bb49094d3358c339b37c47f53"
},
{
"url": "https://git.kernel.org/stable/c/3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1"
},
{
"url": "https://git.kernel.org/stable/c/9faa6b69ad73f03c7bde53e07d75a28822dc9a1a"
},
{
"url": "https://git.kernel.org/stable/c/486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae"
}
],
"title": "btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74321",
"datePublished": "2026-08-15T05:58:17.485Z",
"dateReserved": "2026-08-15T05:44:03.884Z",
"dateUpdated": "2026-08-17T05:45:52.396Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…