CVE-2026-64567
Received Received - Intake

Buffer Overflow in Linux Kernel Btrfs Free Space Cache

Vulnerability report for CVE-2026-64567, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 free space cache, __load_free_space_cache() takes num_entries and num_bitmaps straight from the on-disk btrfs_free_space_header. That header is stored in the tree_root under a key with type 0, which the tree-checker has no case for, so neither count is validated before the load trusts it. The load loops num_entries times and maps the next page whenever the current one runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which does io_ctl->pages[io_ctl->index++]. But pages[] is allocated in io_ctl_init() from the cache inode's i_size, not from num_entries: num_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE); io_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS); So if num_entries claims more records than the pages can hold, io_ctl->index runs off the end of pages[]. The write side never hits this because io_ctl_add_entry() and io_ctl_add_bitmap() both stop once io_ctl->index >= io_ctl->num_pages; the read side just never had the same check. To trigger it, take a clean cache (num_entries = <N> here), set num_entries in the header to 0x10000, and fix up the leaf checksum so it still passes the tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and pages[] is a 16-pointer (kmalloc-128) array. The load now tries to read 65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the array: BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565) Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58 io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565) __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820) load_free_space_cache (fs/btrfs/free-space-cache.c:1017) caching_thread (fs/btrfs/block-group.c:880) btrfs_work_helper (fs/btrfs/async-thread.c:312) process_one_work worker_thread kthread ret_from_fork free-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc() at line 565, which is why that is the frame KASAN names. The out-of-bounds slot is then treated as a struct page and handed to crc32c(), so the bad read turns into a GP fault. Add the missing check to io_ctl_check_crc(), which is where both the entry loop and the bitmap loop end up. When num_entries is too large the load now fails like any corrupt cache: __load_free_space_cache() drops it and rebuilds the free space from the extent tree, so a valid cache is never rejected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability in the btrfs filesystem. It involves a flaw in how free space cache files are loaded. The issue occurs when the number of entries in a cache file exceeds the available pages, causing an out-of-bounds memory access. This happens because the code does not validate the entry count before processing, leading to a buffer overflow when reading corrupted cache files.

Detection Guidance

This vulnerability affects the Linux kernel's Btrfs filesystem, specifically the free space cache handling. Detection requires checking kernel logs for KASAN slab-out-of-bounds errors related to btrfs or io_ctl_check_crc. Monitor system logs with: dmesg | grep -i kasan or journalctl -k | grep -i btrfs. If you suspect exploitation, inspect Btrfs filesystem integrity with btrfs check /dev/sdX.

Impact Analysis

This vulnerability could cause system crashes or kernel panics due to memory corruption. An attacker with local access might exploit it to trigger a denial-of-service condition. It does not allow arbitrary code execution but could destabilize the system by corrupting kernel memory.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It is a Linux kernel memory corruption issue in the btrfs filesystem that could lead to system crashes or data corruption. Compliance impacts would only occur if the vulnerability caused unauthorized data access, loss, or integrity issues in systems handling regulated data.

Mitigation Strategies

Upgrade the Linux kernel to a patched version where this issue is resolved. If immediate patching is not possible, disable Btrfs free space cache v1 by mounting filesystems with nospace_cache or use free space cache v2 if available. Avoid using untrusted Btrfs images or filesystems until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64567. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart