7.8

CVE-2026-64567

btrfs: reject free space cache with more entries than pages

In the Linux kernel, the following vulnerability has been resolved:

btrfs: reject free space cache with more entries than pages

When loading a v1 free space cache, __load_free_space_cache() takes
num_entries and num_bitmaps straight from the on-disk
btrfs_free_space_header. That header is stored in the tree_root under a key
with type 0, which the tree-checker has no case for, so neither count is
validated before the load trusts it.

The load loops num_entries times and maps the next page whenever the current
one runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which
does io_ctl->pages[io_ctl->index++]. But pages[] is allocated in
io_ctl_init() from the cache inode's i_size, not from num_entries:

	num_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE);
	io_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS);

So if num_entries claims more records than the pages can hold, io_ctl->index
runs off the end of pages[]. The write side never hits this because
io_ctl_add_entry() and io_ctl_add_bitmap() both stop once
io_ctl->index >= io_ctl->num_pages; the read side just never had the same
check.

To trigger it, take a clean cache (num_entries = <N> here), set num_entries
in the header to 0x10000, and fix up the leaf checksum so it still passes
the tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and
pages[] is a 16-pointer (kmalloc-128) array. The load now tries to read
65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the
array:

  BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)
  Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58
   io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565)
   __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820)
   load_free_space_cache (fs/btrfs/free-space-cache.c:1017)
   caching_thread (fs/btrfs/block-group.c:880)
   btrfs_work_helper (fs/btrfs/async-thread.c:312)
   process_one_work
   worker_thread
   kthread
   ret_from_fork

free-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc()
at line 565, which is why that is the frame KASAN names. The out-of-bounds
slot is then treated as a struct page and handed to crc32c(), so the bad
read turns into a GP fault.

Add the missing check to io_ctl_check_crc(), which is where both the entry
loop and the bitmap loop end up. When num_entries is too large the load now
fails like any corrupt cache: __load_free_space_cache() drops it and rebuilds
the free space from the extent tree, so a valid cache is never rejected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 5b0e95bf607ddd59b39f52d3d55e6581c817b530
Version < 8ded74c654a982dc8581a17b0caa7fcedb20de69
Status affected
Version 5b0e95bf607ddd59b39f52d3d55e6581c817b530
Version < c9c38066b6446e83668c041702bb639b0ca49363
Status affected
Version 5b0e95bf607ddd59b39f52d3d55e6581c817b530
Version < 094734c7aaa2b36751dc32480a680a4952685e78
Status affected
Version 5b0e95bf607ddd59b39f52d3d55e6581c817b530
Version < 33878ba25e2638bc0c61623d7a05c9ca2b74c039
Status affected
Version 5b0e95bf607ddd59b39f52d3d55e6581c817b530
Version < 404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2
Status affected
Version 5b0e95bf607ddd59b39f52d3d55e6581c817b530
Version < 5e1b2ca6b34939e70fb0785e8222b53cf060016f
Status affected
Version 5b0e95bf607ddd59b39f52d3d55e6581c817b530
Version < f9fef131fa3f59b857217f522fa5ea430d1b707c
Status affected
Version 5b0e95bf607ddd59b39f52d3d55e6581c817b530
Version < a2d8d5647ed854e38f941741aea45b9eb15a6350
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 3.2
Status affected
Version 0
Version < 3.2
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.021
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/33878ba25e2638bc0c61623d7a05c9ca2b74c039
https://git.kernel.org/stable/c/404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2
https://git.kernel.org/stable/c/5e1b2ca6b34939e70fb0785e8222b53cf060016f
https://git.kernel.org/stable/c/f9fef131fa3f59b857217f522fa5ea430d1b707c
https://git.kernel.org/stable/c/a2d8d5647ed854e38f941741aea45b9eb15a6350
https://git.kernel.org/stable/c/094734c7aaa2b36751dc32480a680a4952685e78
https://git.kernel.org/stable/c/8ded74c654a982dc8581a17b0caa7fcedb20de69
https://git.kernel.org/stable/c/c9c38066b6446e83668c041702bb639b0ca49363