PT-2026-35018 · Linux · Linux Kernel

CVE-2026-31666

·

Published

2026-03-31

·

Updated

2026-08-30

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the btrfs component where the lookup extent data ref() function returns an incorrect value after changing a leaf. Specifically, when btrfs next leaf() returns 0, the ret variable is overwritten from -ENOENT to 0. If the first key in the subsequent leaf does not match the required objectid or type, the function returns 0 instead of -ENOENT. This causes the caller to incorrectly assume the lookup succeeded, which may lead to operations on the wrong extent tree item and potential extent tree corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-12601
CVE-2026-31666
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1

Affected Products

Linux Kernel