๐Ÿ” CVE Alert

CVE-2026-74321

UNKNOWN 0.0

btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() In the beginning of the loop, we try to obtain a locked delayed ref head, if 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(), which can return an error pointer. If the error pointer is -EAGAIN we do a continue and go back to the beginning of the loop, which will not try again to call btrfs_select_ref_head() since 'locked_ref' is no longer NULL but it's ERR_PTR(-EAGAIN), and then we do: spin_lock(&locked_ref->lock); against a ERR_PTR(-EAGAIN) value, generating an invalid pointer dereference. Fix this by ensuring that 'locked_ref' is set to NULL when btrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count' as well, to prevent infinite looping. We do this by doing a goto to the bottom of the loop that already sets 'locked_ref' to NULL and does a cond_resched(), with an increment to 'count' right before the goto. These measures were in place before the refactoring in commit 0110a4c43451 ("btrfs: refactor __btrfs_run_delayed_refs loop") but were unintentionally lost afterwards.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 15, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
0110a4c43451533de1ea1bbdc57b5d452f9d8b25 < c372ca227e16bace86f1df1fa4ae6849e2fcfa28 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 < a71143590ce9764dbcb47617647592ff8b4d48bc 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 < 65770111a2d47c2b15e20b2ba92bb12198f289d4 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 < 015dc4a1e0c2cba551d4620eba13d26d5081dc34 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 < ba9fa2ff5981589bb49094d3358c339b37c47f53 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 < 3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 < 9faa6b69ad73f03c7bde53e07d75a28822dc9a1a 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 < 486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae
Linux / Linux
4.20

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c372ca227e16bace86f1df1fa4ae6849e2fcfa28 git.kernel.org: https://git.kernel.org/stable/c/a71143590ce9764dbcb47617647592ff8b4d48bc git.kernel.org: https://git.kernel.org/stable/c/65770111a2d47c2b15e20b2ba92bb12198f289d4 git.kernel.org: https://git.kernel.org/stable/c/015dc4a1e0c2cba551d4620eba13d26d5081dc34 git.kernel.org: https://git.kernel.org/stable/c/ba9fa2ff5981589bb49094d3358c339b37c47f53 git.kernel.org: https://git.kernel.org/stable/c/3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1 git.kernel.org: https://git.kernel.org/stable/c/9faa6b69ad73f03c7bde53e07d75a28822dc9a1a git.kernel.org: https://git.kernel.org/stable/c/486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae