PT-2026-104976 · Azure Linux · Kernel

Published

2026-09-24

·

Updated

2026-09-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
btrfs: tree-checker: validate names in ROOT REF and ROOT BACKREF
ROOT REF and ROOT BACKREF items contain a struct btrfs root ref followed by the subvolume name. Several readers assume that this layout is already valid and then use the on-disk name length directly. A corrupted item can therefore make those readers address bytes outside the item, and BTRFS IOC GET SUBVOL INFO can copy too many bytes into its fixed-size UAPI name buffer.
Validate ROOT REF and ROOT BACKREF items in tree-checker before any reader uses them. Reject records that do not contain a non-empty name, whose name len does not exactly describe the remaining item payload, or whose name exceeds BTRFS NAME LEN.
For BTRFS IOC GET SUBVOL INFO, copy only the validated on-disk name len instead of deriving the copy length from the item size. The ioctl result is zeroed when allocated. That leaves the existing trailing zero byte untouched.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103943

Affected Products

Kernel