7.5

CVE-2026-74321

btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()

In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()

In the beginning of the loop, we try to obtain a locked delayed ref head,
if 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(),
which can return an error pointer. If the error pointer is -EAGAIN we do
a continue and go back to the beginning of the loop, which will not try
again to call btrfs_select_ref_head() since 'locked_ref' is no longer
NULL but it's ERR_PTR(-EAGAIN), and then we do:

   spin_lock(&locked_ref->lock);

against a ERR_PTR(-EAGAIN) value, generating an invalid pointer
dereference.

Fix this by ensuring that 'locked_ref' is set to NULL when
btrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count'
as well, to prevent infinite looping. We do this by doing a goto to the
bottom of the loop that already sets 'locked_ref' to NULL and does a
cond_resched(), with an increment to 'count' right before the goto.
These measures were in place before the refactoring in commit 0110a4c43451
("btrfs: refactor __btrfs_run_delayed_refs loop") but were unintentionally
lost afterwards.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 0110a4c43451533de1ea1bbdc57b5d452f9d8b25
Version < c372ca227e16bace86f1df1fa4ae6849e2fcfa28
Status affected
Version 0110a4c43451533de1ea1bbdc57b5d452f9d8b25
Version < a71143590ce9764dbcb47617647592ff8b4d48bc
Status affected
Version 0110a4c43451533de1ea1bbdc57b5d452f9d8b25
Version < 65770111a2d47c2b15e20b2ba92bb12198f289d4
Status affected
Version 0110a4c43451533de1ea1bbdc57b5d452f9d8b25
Version < 015dc4a1e0c2cba551d4620eba13d26d5081dc34
Status affected
Version 0110a4c43451533de1ea1bbdc57b5d452f9d8b25
Version < ba9fa2ff5981589bb49094d3358c339b37c47f53
Status affected
Version 0110a4c43451533de1ea1bbdc57b5d452f9d8b25
Version < 3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1
Status affected
Version 0110a4c43451533de1ea1bbdc57b5d452f9d8b25
Version < 9faa6b69ad73f03c7bde53e07d75a28822dc9a1a
Status affected
Version 0110a4c43451533de1ea1bbdc57b5d452f9d8b25
Version < 486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 4.20
Status affected
Version 0
Version < 4.20
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.41
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/c372ca227e16bace86f1df1fa4ae6849e2fcfa28
https://git.kernel.org/stable/c/a71143590ce9764dbcb47617647592ff8b4d48bc
https://git.kernel.org/stable/c/65770111a2d47c2b15e20b2ba92bb12198f289d4
https://git.kernel.org/stable/c/015dc4a1e0c2cba551d4620eba13d26d5081dc34
https://git.kernel.org/stable/c/ba9fa2ff5981589bb49094d3358c339b37c47f53
https://git.kernel.org/stable/c/3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1
https://git.kernel.org/stable/c/9faa6b69ad73f03c7bde53e07d75a28822dc9a1a
https://git.kernel.org/stable/c/486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae