Executive brief
A vulnerability in the Linux kernel's Btrfs file system could allow a local user to cause system instability or data corruption. The issue occurs when the system incorrectly manages memory pages during write operations, particularly on specialized storage setups like zoned drives. This can lead to a kernel crash (BUG) or failures in ensuring data is properly saved to disk before other operations occur.
Technical details
A race condition exists in the Btrfs subpage support where btrfs_subpage_set_writeback() prematurely clears the PAGECACHE_TAG_TOWRITE tag. When a folio is partially written (e.g., in zoned mode or compressed writes), clearing this tag while blocks remain dirty causes concurrent WB_SYNC_ALL writeback processes to skip the folio. This breaks ordering guarantees required by btrfs_wait_ordered_extents(), potentially leading to use-after-free scenarios or kernel BUG assertions during file truncation or I/O finishing. The fix ensures the TOWRITE tag is retained until the entire folio is clean.
Affected products
- Linux Linux Kernel 6.12 to 6.16-rc6
Timeline
- 2025-08-22: patched: Initial patch authored
- 2025-09-11: disclosed: CVE published