Btrfs Free Space Cache Vulnerability in Linux Kernel
CVE-2026-64567
What is CVE-2026-64567?
A vulnerability in the Btrfs free space cache within the Linux kernel allows unauthorized memory access during the loading process due to inadequate validation of entry counts. When loading a version 1 free space cache, the system relies on values from the on-disk Btrfs free space header without proper checks. If an attacker manipulates these values, it can result in reading beyond allocated memory, possibly leading to data corruption or crashes. This flaw necessitates the implementation of additional checks to safeguard against corrupted cache data and ensure stability.
Affected Version(s)
Linux 5b0e95bf607ddd59b39f52d3d55e6581c817b530 < 33878ba25e2638bc0c61623d7a05c9ca2b74c039
Linux 5b0e95bf607ddd59b39f52d3d55e6581c817b530 < 404a0b986e0b6e79738fdf1f0ebbbc43b9acd2a2
Linux 5b0e95bf607ddd59b39f52d3d55e6581c817b530 < 5e1b2ca6b34939e70fb0785e8222b53cf060016f