Junglewise Threat Intelligence

CVE-2026-68442: Linux kernel btrfs use-after-free in extent map splitting

CVE-2026-68442 · Severity: high · CVSS 7.8 · Published 2026-08-12

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's btrfs filesystem contains a use-after-free vulnerability in extent map handling. When the kernel splits extent maps during file operations, it incorrectly inherits a logging flag that should not be propagated, leading to memory corruption and potential system instability or crashes when the affected memory is later reused.

Technical details

The vulnerability is a use-after-free flaw in the btrfs extent map handling code (fs/btrfs/extent_map.c). When btrfs_drop_extent_map_range() splits an extent map, the EXTENT_FLAG_LOGGING flag is incorrectly propagated to the newly created split maps due to a regression introduced in commit f86f7a75e2fb. The flag should only remain on the original map but be cleared on splits. Since the flag is never cleared, when the split extent map is freed while still present on the inode's modified_extents list (such as by the extent map shrinker), it triggers a use-after-free condition. This requires local filesystem access and can be triggered through normal file operations on a btrfs-formatted volume. The fix clears EXTENT_FLAG_LOGGING from the local flags copy used for splits while only clearing EXTENT_FLAG_PINNED from the original map's flags.

Affected products

  • Linux Linux kernel 5.15 and later, affecting stable kernel versions through 6.x series

Timeline

  • 2026-08-12: disclosed
  • 2026-06-30: patched: Fix committed upstream

References

Related threats