Executive brief
A vulnerability in the Linux kernel's Btrfs file system could lead to system instability or data corruption. When a specific experimental feature (EXTENT_TREE_V2) is enabled, the system incorrectly manages internal memory lists during file system operations. This can cause the system to crash or abort transactions, potentially leading to a loss of availability or file system errors.
Technical details
A vulnerability in the Btrfs file system component of the Linux kernel arises from improper list management when the EXTENT_TREE_V2 incompat flag is enabled. The kernel unconditionally adds the block group tree to the 'switch_commits' list using 'list_add_tail()', even though the block group root may already be linked via its 'dirty_list' field. This double-addition results in corruption of the prev/next pointers in the linked list. This corruption can trigger a kernel panic (detected by CONFIG_DEBUG_LIST) or cause the 'switch_commits' and 'dirty_cowonly_roots' lists to become intermingled, eventually leading to a transaction abort when the kernel fails to find a root key. The issue has been resolved in multiple stable kernel branches.
Affected products
- Linux Linux Kernel 6.18.0
Timeline
- 2025-12-22: other: Patch authored
- 2026-02-26: patched: Patch committed to stable tree
- 2026-06-03: disclosed: CVE published
References
- https://git.kernel.org/stable/c/201091da34c4f113af6b4a7407091c39bf29d4ca
- https://git.kernel.org/stable/c/3a1f4264daed4b419c325a7fe35e756cada3cf82
- https://git.kernel.org/stable/c/4eb830847d84276f1c8ea46541cfeeedaba1fb63
- https://git.kernel.org/stable/c/6e10283b5519d987d880d71bec90cdc7f2ec62b3
- https://git.kernel.org/stable/c/80e1fda9c084dcf54819a12bc7682ec0afd2d8f4
- https://git.kernel.org/stable/c/e3d1fd084319f8f0830b22f014c7af6a96b4497b