NULL Pointer Dereference in Btrfs on Linux Kernel for Rescue Mounts
CVE-2026-74571
What is CVE-2026-74571?
A recent vulnerability identified in Btrfs on the Linux Kernel affects systems during rescue mounts, potentially causing a NULL pointer dereference when block group trees are corrupted. This issue arises with the 'rescue=ibadroots' parameter, allowing a mount to proceed even if crucial root pointers are NULL. As a result, functions like btrfs_update_global_block_rsv() may dereference a NULL pointer, leading to crashes. The resolution involves ensuring that rescue mounts remain read-only and properly managing the global block reserve accounting to prevent such dereferences.
Affected Version(s)
Linux 8dbfc14fc736eb701089aff09645c3d4ad3decb1 < 076349e4c8d11f6b58c4549976a513b2b4dc6df2
Linux 8dbfc14fc736eb701089aff09645c3d4ad3decb1 < 51a0e8399858621442807a26057bcd1cd3ced046
Linux cbec34d3021d47007a0334c634f7053dbaf93d02