Executive brief
A vulnerability in the Linux kernel's Btrfs file system could cause a system to fail to start or mount its storage after an unexpected power failure. This occurs when specific file renaming operations are performed just before a crash, leading the system to incorrectly attempt to delete important data during recovery. In practice, this results in a denial of service where the affected storage volume becomes inaccessible.
Technical details
A vulnerability exists in the Btrfs implementation within the Linux kernel where conflicting inodes are not always detected when logging inode references. Specifically, during a rename exchange involving directories, the 'last_unlink_trans' is not updated for directory inodes. If a subsequent fsync occurs on a child file, the log tree may end up in an inconsistent state where one inode is logged but its rename-exchanged counterpart is not. Upon power failure and subsequent log replay, the kernel attempts to delete the unlogged inode to resolve a name conflict; if that inode is a directory containing a subvolume, 'replay_dir_deletes' and '__btrfs_unlink_inode' fail because they cannot handle directory items pointing to root items, resulting in a transaction abort and mount failure. Patches have been released for stable kernel branches.
Affected products
- Linux Linux Kernel 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.12.y
Timeline
- 2025-12-11: disclosed: Initial patch submission by Filipe Manana
- 2026-01-17: patched: Merged into stable kernel trees
- 2026-01-31: advisory: CVE-2025-71183 published
References
- https://git.kernel.org/stable/c/0c2413c69129f6ce60157f7b53d9ba880260400b
- https://git.kernel.org/stable/c/7ba0b6461bc4edb3005ea6e00cdae189bcf908a5
- https://git.kernel.org/stable/c/a63998cd6687c14b160dccb0bbcf281b2eb0dab3
- https://git.kernel.org/stable/c/c7f0207db68d5a1b4af23acbef1a8e8ddc431ebb
- https://git.kernel.org/stable/c/d52af58dd463821c5c516aebb031a58934f696ea