Null Pointer Dereference in Btrfs Affects Linux Kernel Products
CVE-2026-64593

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-64593?

A vulnerability in the Btrfs filesystem within the Linux kernel has been identified that results in a null pointer dereference due to improper handling of device states. Specifically, when a device is marked as missing and later re-scanned, the BTRFS_DEV_STATE_WRITEABLE flag may not be set, leaving the device's bdev pointer as NULL. This can cause the filesystem to crash during operations that attempt to trim free extents, leading to potential service disruptions. Proper synchronization and management of device state transitions are essential for maintaining system stability and preventing such errors.

Affected Version(s)

Linux 499f377f49f085ee4aa214c738e948e88626f39b

Linux 499f377f49f085ee4aa214c738e948e88626f39b < 210af872eafa0cf572a84cb303c0f9d2914c1226

Linux 499f377f49f085ee4aa214c738e948e88626f39b < 3d8fa4b828a86b33c60858e58aaab6df273ede05

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.