-

CVE-2026-97416

btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk()

In the Linux kernel, the following vulnerability has been resolved:

btrfs: balance: fix potential bg lookup failure in btrfs_may_alloc_data_chunk()

[BUG]
Running btrfs balance can trigger a null-ptr-deref before relocating a
data chunk when metadata corruption leaves a chunk in the chunk tree
without a corresponding block group in the in-memory cache:

  KASAN: null-ptr-deref in range [0x0000000000000088-0x000000000000008f]
  RIP: 0010:btrfs_may_alloc_data_chunk+0x40/0x1c0 fs/btrfs/volumes.c:3601
  Call Trace:
    __btrfs_balance fs/btrfs/volumes.c:4217 [inline]
    btrfs_balance+0x2516/0x42b0 fs/btrfs/volumes.c:4604
    btrfs_ioctl_balance fs/btrfs/ioctl.c:3577 [inline]
    btrfs_ioctl+0x25cf/0x5b90 fs/btrfs/ioctl.c:5313
    ...

[CAUSE]
__btrfs_balance() iterates the on-disk chunk tree and passes the chunk
logical bytenr to btrfs_may_alloc_data_chunk() before relocating a data
chunk. That helper then queries the in-memory block group cache:

  cache = btrfs_lookup_block_group(fs_info, chunk_offset);
  chunk_type = cache->flags;   /* cache may be NULL */

A corrupt image can contain a chunk item whose matching block group
item is missing, so no block group is ever inserted into the cache. In
that case btrfs_lookup_block_group() returns NULL.

The code only guards this with ASSERT(cache), which becomes a no-op when
CONFIG_BTRFS_ASSERT is disabled. The subsequent dereference of
cache->flags therefore crashes the kernel.

[FIX]
Add a NULL check after btrfs_lookup_block_group() in
btrfs_may_alloc_data_chunk() and print and error message for clarity.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a6f93c71d412ba8ed743152c3a54ad0b78dcd9c7
Version < 9f37a6d6ae9e998232e2ba091ab4999cdf967e1b
Status affected
Version a6f93c71d412ba8ed743152c3a54ad0b78dcd9c7
Version < e479236a8f4d85c4fb6b3f7c2556c21f583e2bf2
Status affected
Version a6f93c71d412ba8ed743152c3a54ad0b78dcd9c7
Version < 322f891b4d4fe64acb3351a0ffa62a7fa5ba7256
Status affected
Version a6f93c71d412ba8ed743152c3a54ad0b78dcd9c7
Version < 81a664ed8b1a44c76b204c4bd0d751317a02c5cd
Status affected
Version a6f93c71d412ba8ed743152c3a54ad0b78dcd9c7
Version < 9740dd0c17a4be8cc47a06c5ca5293471a7e286e
Status affected
Version a6f93c71d412ba8ed743152c3a54ad0b78dcd9c7
Version < 59f75e0c8724d4adebc08c7dd3ff2358b80c21f7
Status affected
Version a6f93c71d412ba8ed743152c3a54ad0b78dcd9c7
Version < 18d32b0013efba19f7ad3e5b08d7aee813d604a6
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.16
Status affected
Version 0
Version < 4.16
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/9740dd0c17a4be8cc47a06c5ca5293471a7e286e
https://git.kernel.org/stable/c/59f75e0c8724d4adebc08c7dd3ff2358b80c21f7
https://git.kernel.org/stable/c/18d32b0013efba19f7ad3e5b08d7aee813d604a6
https://git.kernel.org/stable/c/322f891b4d4fe64acb3351a0ffa62a7fa5ba7256
https://git.kernel.org/stable/c/81a664ed8b1a44c76b204c4bd0d751317a02c5cd
https://git.kernel.org/stable/c/9f37a6d6ae9e998232e2ba091ab4999cdf967e1b
https://git.kernel.org/stable/c/e479236a8f4d85c4fb6b3f7c2556c21f583e2bf2