7.8

CVE-2026-68442

btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps

In the Linux kernel, the following vulnerability has been resolved:

btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps

When btrfs_drop_extent_map_range() splits an extent map, the new split
maps inherit the original map's flags through a local 'flags' variable.
Commit f86f7a75e2fb ("btrfs: use the flags of an extent map to identify
the compression type") changed the EXTENT_FLAG_LOGGING clearing to
operate on em->flags instead of that local 'flags' copy, so a split of
an extent map that is currently being logged wrongly inherits
EXTENT_FLAG_LOGGING.

The flag is then never cleared on the split, and when it is freed while
still on the inode's modified_extents list (for example by the extent
map shrinker) it trips the WARN_ON(!list_empty(&em->list)) in
btrfs_free_extent_map() and leads to a use-after-free.

Clear EXTENT_FLAG_LOGGING from the local 'flags' copy used for the
splits and only clear EXTENT_FLAG_PINNED from em->flags, restoring the
behaviour prior to f86f7a75e2fb.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f86f7a75e2fb5fd7d31d00eab8a392f97ba42ce9
Version < 2a9246a424f45f33a1b8367052611ebe874868ad
Status affected
Version f86f7a75e2fb5fd7d31d00eab8a392f97ba42ce9
Version < 9304713b70e7e1450e3a76e758836fe5391bfa95
Status affected
Version f86f7a75e2fb5fd7d31d00eab8a392f97ba42ce9
Version < 0e465c63f103a5ce6849614d6bda048d70eebec8
Status affected
Version f86f7a75e2fb5fd7d31d00eab8a392f97ba42ce9
Version < 5eff4d5b17fa1950e80bfd1ba43dc0699e61a644
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.8
Status affected
Version 0
Version < 6.8
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.019
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0e465c63f103a5ce6849614d6bda048d70eebec8
https://git.kernel.org/stable/c/2a9246a424f45f33a1b8367052611ebe874868ad
https://git.kernel.org/stable/c/5eff4d5b17fa1950e80bfd1ba43dc0699e61a644
https://git.kernel.org/stable/c/9304713b70e7e1450e3a76e758836fe5391bfa95