PT-2026-79728 · Linux · Linux Kernel

CVE-2026-74723

·

Published

2026-08-22

·

Updated

2026-08-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the btrfs module when processing inline LZO compressed file extents. When a crafted btrfs image is used, the lzo decompress() function may attempt to read a segment header even if the extent contains only an LZO header without a corresponding segment header or payload. This leads to a slab-out-of-bounds read beyond the item boundary. If the affected extent is the first item of the leaf, the read extends beyond the extent buffer boundary, which can be detected by KASAN (Kernel Address Sanitizer), a dynamic memory error detector for the kernel.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-97308
CVE-2026-74723

Affected Products

Linux Kernel