Executive brief
A vulnerability was identified in the Linux kernel's Btrfs file system component that could lead to a system crash. The issue occurs during specific error handling scenarios when the system fails to initialize internal tracking structures, causing the memory to be released twice. This type of error typically impacts system stability and availability.
Technical details
A double-free vulnerability exists in fs/btrfs/space-info.c within the Linux kernel. When kobject_init_and_add() fails inside btrfs_sysfs_add_space_info_type(), the kobject_put() call triggers the release callback which frees the 'sub_group' memory. However, the calling function create_space_info_sub_group() also attempts to kfree() the same pointer upon receiving the error return. This flaw is reachable via local interactions that trigger Btrfs space information sub-group creation. The fix involves removing the redundant kfree() and allowing the kobject release mechanism to handle the cleanup exclusively.
Affected products
- Linux Linux kernel 6.18+
Timeline
- 2026-05-28: advisory: CVE-2026-46164 published by NVD
- 2026-05-28: patched: Fixes merged into various stable kernel branches
References
- https://git.kernel.org/stable/c/14b22be1dd844383eb03af9b1ee3b6b25d32aeaf
- https://git.kernel.org/stable/c/259af6857a1b4f1e9ef8b780353f9d11c26a22bd
- https://git.kernel.org/stable/c/a7449edf96143f192606ec8647e3167e1ecbd728
- https://git.kernel.org/stable/c/d2a675f2e238ec96c8e91e2718c1f910c9c8fb21
- https://git.kernel.org/stable/c/dfd05a16b5c9d1d98b47905f37f2fccda52173d1