PT-2026-104976 · Azure Linux · Kernel

Publicado

2026-09-24

·

Atualizado

2026-09-24

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
btrfs: tree-checker: validate names in ROOT REF and ROOT BACKREF
ROOT REF and ROOT BACKREF items contain a struct btrfs root ref followed by the subvolume name. Several readers assume that this layout is already valid and then use the on-disk name length directly. A corrupted item can therefore make those readers address bytes outside the item, and BTRFS IOC GET SUBVOL INFO can copy too many bytes into its fixed-size UAPI name buffer.
Validate ROOT REF and ROOT BACKREF items in tree-checker before any reader uses them. Reject records that do not contain a non-empty name, whose name len does not exactly describe the remaining item payload, or whose name exceeds BTRFS NAME LEN.
For BTRFS IOC GET SUBVOL INFO, copy only the validated on-disk name len instead of deriving the copy length from the item size. The ioctl result is zeroed when allocated. That leaves the existing trailing zero byte untouched.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

AZL-103943

Produtos afetados

Kernel