Junglewise Threat Intelligence

CVE-2026-46251: Linux Kernel Btrfs dirty_list corruption in block_group_tree

CVE-2026-46251 · Severity: info · CVSS 0 · Published 2026-06-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Btrfs file system could lead to system instability or data corruption. When a specific experimental feature (EXTENT_TREE_V2) is enabled, the system incorrectly manages internal memory lists during file system operations. This can cause the system to crash or abort transactions, potentially leading to a loss of availability or file system errors.

Technical details

A vulnerability in the Btrfs file system component of the Linux kernel arises from improper list management when the EXTENT_TREE_V2 incompat flag is enabled. The kernel unconditionally adds the block group tree to the 'switch_commits' list using 'list_add_tail()', even though the block group root may already be linked via its 'dirty_list' field. This double-addition results in corruption of the prev/next pointers in the linked list. This corruption can trigger a kernel panic (detected by CONFIG_DEBUG_LIST) or cause the 'switch_commits' and 'dirty_cowonly_roots' lists to become intermingled, eventually leading to a transaction abort when the kernel fails to find a root key. The issue has been resolved in multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 6.18.0

Timeline

  • 2025-12-22: other: Patch authored
  • 2026-02-26: patched: Patch committed to stable tree
  • 2026-06-03: disclosed: CVE published

References