PT-2026-6113 · Btrfs+1 · Btrfs+1

CVE-2026-23043

·

Published

2026-01-01

·

Updated

2026-02-10

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A NULL pointer dereference issue exists in the do abort log replay() function within the Btrfs log replay component of the Linux kernel. The issue, identified by Coverity (CID 1666756), occurs when btrfs alloc path() fails during buffer replay, resulting in a NULL value for wc->subvol path. Subsequently, btrfs abort log replay() unconditionally dereferences this NULL pointer when attempting to print debug information. The fix involves adding a NULL check before dereferencing wc->subvol path within do abort log replay().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-13795
CVE-2026-23043

Affected Products

Btrfs
Linux Kernel