Executive brief
A vulnerability exists in the Linux kernel's Btrfs file system when managing disk quotas. A race condition between disabling quotas and rescanning them can lead to a system crash or potential unauthorized data access. This issue primarily affects local users on systems utilizing Btrfs with quota features enabled.
Technical details
A race condition exists between btrfs_quota_disable() and btrfs_ioctl_quota_rescan() in the Btrfs implementation. When quotas are disabled, the kernel may begin freeing qgroup records from the fs_info->qgroup_tree rbtree without holding the necessary qgroup_lock. Simultaneously, a rescan task may attempt to iterate through the same tree while holding the lock, leading to a use-after-free (UAF) scenario. The vulnerability is triggered because btrfs_quota_disable() fails to wait for a rescan task that has started but not yet set the 'running' flag. The fix involves ensuring the qgroup_lock is held during configuration cleanup and verifying quota status before starting rescan workers.
Affected products
- Linux Linux Kernel 3.12 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-09-11: disclosed
- 2025-09-11: advisory
- 2025-08-20: patched: Initial patch committed to stable tree
References
- https://git.kernel.org/stable/c/2fd0f5ceb997f90f4332ccbab6c7e907e6b2d0eb
- https://git.kernel.org/stable/c/7cda0fdde5d9890976861421d207870500f9aace
- https://git.kernel.org/stable/c/b172535ccba12f0cf7d23b3b840989de47fc104d
- https://git.kernel.org/stable/c/c38028ce0d0045ca600b6a8345a0ff92bfb47b66
- https://git.kernel.org/stable/c/dd0b28d877b293b1d7f8727a7de08ae36b6b9ef0
- https://git.kernel.org/stable/c/e1249667750399a48cafcf5945761d39fa584edf
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html