PT-2026-79728 · Linux · Linux Kernel
CVE-2026-74723
·
Published
2026-08-22
·
Updated
2026-08-27
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the btrfs module when processing inline LZO compressed file extents. When a crafted btrfs image is used, the
lzo decompress() function may attempt to read a segment header even if the extent contains only an LZO header without a corresponding segment header or payload. This leads to a slab-out-of-bounds read beyond the item boundary. If the affected extent is the first item of the leaf, the read extends beyond the extent buffer boundary, which can be detected by KASAN (Kernel Address Sanitizer), a dynamic memory error detector for the kernel.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel