PT-2026-104976 · Azure Linux · Kernel
Publicado
2026-09-24
·
Atualizado
2026-09-24
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
btrfs: tree-checker: validate names in ROOT REF and ROOT BACKREF
ROOT REF and ROOT BACKREF items contain a struct btrfs root ref followed
by the subvolume name. Several readers assume that this layout is already
valid and then use the on-disk name length directly. A corrupted item can
therefore make those readers address bytes outside the item, and
BTRFS IOC GET SUBVOL INFO can copy too many bytes into its fixed-size UAPI
name buffer.
Validate ROOT REF and ROOT BACKREF items in tree-checker before any reader
uses them. Reject records that do not contain a non-empty name, whose
name len does not exactly describe the remaining item payload, or whose
name exceeds BTRFS NAME LEN.
For BTRFS IOC GET SUBVOL INFO, copy only the validated on-disk name len
instead of deriving the copy length from the item size. The ioctl result is
zeroed when allocated. That leaves the existing trailing zero byte
untouched.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Kernel