Btrfs Free Space Cache Vulnerability in Linux Kernel
CVE-2026-64567

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-64567?

A vulnerability in the Btrfs free space cache within the Linux kernel allows unauthorized memory access during the loading process due to inadequate validation of entry counts. When loading a version 1 free space cache, the system relies on values from the on-disk Btrfs free space header without proper checks. If an attacker manipulates these values, it can result in reading beyond allocated memory, possibly leading to data corruption or crashes. This flaw necessitates the implementation of additional checks to safeguard against corrupted cache data and ensure stability.

Affected Version(s)

Linux 5b0e95bf607ddd59b39f52d3d55e6581c817b530 < 33878ba25e2638bc0c61623d7a05c9ca2b74c039

Linux 5b0e95bf607ddd59b39f52d3d55e6581c817b530 < 404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2

Linux 5b0e95bf607ddd59b39f52d3d55e6581c817b530 < 5e1b2ca6b34939e70fb0785e8222b53cf060016f

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.