Executive brief
A synchronization issue was identified in the Linux kernel's Btrfs file system component. This flaw could lead to system instability or crashes when the system attempts to manage memory for certain file storage operations. While primarily a technical bug, it could impact the reliability and availability of servers using the Btrfs file system.
Technical details
A synchronization bug exists in the Btrfs implementation within the Linux kernel, specifically in the `try_release_subpage_extent_buffer()` function in `fs/btrfs/extent_io.c`. The function failed to properly balance Read-Copy-Update (RCU) locks when exiting a loop via a `break` statement in an error path. Because a call to `rcu_read_unlock()` exists immediately after the loop, exiting the loop without an active lock results in an unbalanced unlock operation. This issue was identified using the Clang thread-safety analyzer and has been resolved by adding a missing `rcu_read_lock()` before the loop break. The vulnerability affects kernel versions 6.18 and newer.
Affected products
- Linux Linux Kernel 6.18+
Timeline
- 2026-02-25: other: Patch authored
- 2026-03-19: patched: Patch committed to stable tree
- 2026-05-08: advisory: NVD publication date