Junglewise Threat Intelligence

CVE-2026-46159: Linux Kernel Btrfs information leak in btrfs_ioctl_space_info

CVE-2026-46159 · Severity: info · CVSS 4.4 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Btrfs file system could allow a local user to access sensitive information from the system's memory. The issue occurs when the system incorrectly handles requests for file system space information, potentially leaking data that should remain private. This could be used by an attacker to gain insights into other processes or system operations, though it does not directly allow for system takeover or data destruction.

Technical details

A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in btrfs_ioctl_space_info() within the Btrfs file system implementation. The function performs two passes over block group RAID type lists: the first pass calculates the required buffer size, and the second pass fills it. Because the 'groups_sem' lock is released between these passes, a concurrent block group removal can decrease the actual entry count. If the second pass finds fewer entries than the first, the kernel may copy uninitialized heap memory (trailing bytes from the original allocation) back to userspace via copy_to_user(). This vulnerability allows a local attacker with access to the Btrfs ioctl to leak sensitive kernel heap data. The fix involves using kzalloc() to zero-initialize the buffer and ensuring only the actually-filled number of entries are copied to the user.

Affected products

  • Linux Linux Kernel 3.0 and later

Timeline

  • 2026-03-22: disclosed: Initial patch authored
  • 2026-05-14: patched: Patched in various stable branches
  • 2026-05-28: advisory: CVE published to NVD

References