PT-2026-104976 · Azure Linux · Kernel
Published
2026-09-24
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
btrfs: tree-checker: validate names in ROOT REF and ROOT BACKREF
ROOT REF and ROOT BACKREF items contain a struct btrfs root ref followed
by the subvolume name. Several readers assume that this layout is already
valid and then use the on-disk name length directly. A corrupted item can
therefore make those readers address bytes outside the item, and
BTRFS IOC GET SUBVOL INFO can copy too many bytes into its fixed-size UAPI
name buffer.
Validate ROOT REF and ROOT BACKREF items in tree-checker before any reader
uses them. Reject records that do not contain a non-empty name, whose
name len does not exactly describe the remaining item payload, or whose
name exceeds BTRFS NAME LEN.
For BTRFS IOC GET SUBVOL INFO, copy only the validated on-disk name len
instead of deriving the copy length from the item size. The ioctl result is
zeroed when allocated. That leaves the existing trailing zero byte
untouched.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kernel