Junglewise Threat Intelligence

CVE-2025-71183: Linux Kernel Btrfs mount failure during log replay after rename exchange

CVE-2025-71183 · Severity: critical · CVSS 9.1 · Published 2026-01-31

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Btrfs file system could cause a system to fail to start or mount its storage after an unexpected power failure. This occurs when specific file renaming operations are performed just before a crash, leading the system to incorrectly attempt to delete important data during recovery. In practice, this results in a denial of service where the affected storage volume becomes inaccessible.

Technical details

A vulnerability exists in the Btrfs implementation within the Linux kernel where conflicting inodes are not always detected when logging inode references. Specifically, during a rename exchange involving directories, the 'last_unlink_trans' is not updated for directory inodes. If a subsequent fsync occurs on a child file, the log tree may end up in an inconsistent state where one inode is logged but its rename-exchanged counterpart is not. Upon power failure and subsequent log replay, the kernel attempts to delete the unlogged inode to resolve a name conflict; if that inode is a directory containing a subvolume, 'replay_dir_deletes' and '__btrfs_unlink_inode' fail because they cannot handle directory items pointing to root items, resulting in a transaction abort and mount failure. Patches have been released for stable kernel branches.

Affected products

  • Linux Linux Kernel 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.12.y

Timeline

  • 2025-12-11: disclosed: Initial patch submission by Filipe Manana
  • 2026-01-17: patched: Merged into stable kernel trees
  • 2026-01-31: advisory: CVE-2025-71183 published

References