{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-97415","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-24T14:53:16.867Z","datePublished":"2026-09-24T16:03:22.780Z","dateUpdated":"2026-10-03T10:58:06.771Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:58:06.771Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF\n\nROOT_REF and ROOT_BACKREF items contain a struct btrfs_root_ref followed\nby the subvolume name. Several readers assume that this layout is already\nvalid and then use the on-disk name length directly. A corrupted item can\ntherefore make those readers address bytes outside the item, and\nBTRFS_IOC_GET_SUBVOL_INFO can copy too many bytes into its fixed-size UAPI\nname buffer.\n\nValidate ROOT_REF and ROOT_BACKREF items in tree-checker before any reader\nuses them. Reject records that do not contain a non-empty name, whose\nname_len does not exactly describe the remaining item payload, or whose\nname exceeds BTRFS_NAME_LEN.\n\nFor BTRFS_IOC_GET_SUBVOL_INFO, copy only the validated on-disk name_len\ninstead of deriving the copy length from the item size. The ioctl result is\nzeroed when allocated. That leaves the existing trailing zero byte\nuntouched."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled bytes are the on-disk BTRFS_ROOT_BACKREF_KEY item (struct btrfs_root_ref plus the following name) in the tree of tree roots. After that image is mounted, ioctl(BTRFS_IOC_GET_SUBVOL_INFO) reaches _btrfs_ioctl_get_subvol_info() via btrfs_ioctl() and read_extent_buffer()s the item; no SMB/NFS/packet field carries that payload.\nAC:L - check_leaf_item() had no BTRFS_ROOT_REF_KEY/BTRFS_ROOT_BACKREF_KEY case, so btrfs_check_leaf() accepted a ROOT_BACKREF whose item_size filled the leaf (~BTRFS_LEAF_DATA_SIZE). _btrfs_ioctl_get_subvol_info() then copied item_size-sizeof(struct btrfs_root_ref) into name[256] on every ioctl; the attacker fully controls that image.\nPR:L - btrfs_ioctl() dispatches BTRFS_IOC_GET_SUBVOL_INFO and BTRFS_IOC_INO_LOOKUP_USER with no capable() check. btrfs_fs_type has no FS_USERNS_MOUNT, so the severe case is an unprivileged session user whose USB/loop btrfs image is mounted by udisks2/polkit, then opens any fd in that subvolume and issues the ioctl.\nUI:N - The attacker crafts the ROOT_BACKREF, has that local image mounted, and themselves calls BTRFS_IOC_GET_SUBVOL_INFO (or BTRFS_IOC_INO_LOOKUP_USER, which copies the same item via btrfs_search_path_in_tree_user()) on their own fd. Automount of that local/removable image is not a separate victim action once AV is Local.\nS:U - The overflow is in the host kernel's kzalloc'd btrfs_ioctl_get_subvol_info_args (and ino_lookup_user args) while parsing tree_root ROOT_BACKREF/ROOT_REF items. No KVM/Xen guest-to-host, IOMMU, or sandbox boundary is crossed.\nC:H - _btrfs_ioctl_get_subvol_info() and btrfs_search_path_in_tree_user() call read_extent_buffer() with a length taken from the on-disk item_size into name[BTRFS_VOL_NAME_MAX+1] (256 bytes). That out-of-bounds write of attacker-chosen leaf bytes into adjacent slab is a kernel-memory disclosure primitive.\nI:H - The same unbounded read_extent_buffer() into the 256-byte name[] of the kzalloc'd ioctl args overwrites neighboring heap objects with attacker-controlled ROOT_BACKREF payload, which is sufficient for an arbitrary kernel write and control-flow hijacking.\nA:H - Copying a leaf-sized ROOT_BACKREF past btrfs_ioctl_get_subvol_info_args.name[256], or writing args->name[item_len]='\\0' in btrfs_search_path_in_tree_user() with that huge item_len, oopses or panics the kernel on the slab out-of-bounds access."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/ioctl.c","fs/btrfs/tree-checker.c"],"versions":[{"version":"b64ec075bded2b30bcd90af5aa5256d2237c885d","lessThan":"1370badf6b823ce3cde39a65f46f9e5dc7b4bf43","status":"affected","versionType":"git"},{"version":"b64ec075bded2b30bcd90af5aa5256d2237c885d","lessThan":"ba6c4fc662853f6662e4db060cf88ee994053e21","status":"affected","versionType":"git"},{"version":"b64ec075bded2b30bcd90af5aa5256d2237c885d","lessThan":"9154542070ca7eadb3c764a882f39a127677854b","status":"affected","versionType":"git"},{"version":"b64ec075bded2b30bcd90af5aa5256d2237c885d","lessThan":"74f577c722c99248d804eca18e7de7c5e47549d7","status":"affected","versionType":"git"},{"version":"b64ec075bded2b30bcd90af5aa5256d2237c885d","lessThan":"0af37c217edf15fa21dac1c40822086df356c6bb","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/ioctl.c","fs/btrfs/tree-checker.c"],"versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/1370badf6b823ce3cde39a65f46f9e5dc7b4bf43"},{"url":"https://git.kernel.org/stable/c/ba6c4fc662853f6662e4db060cf88ee994053e21"},{"url":"https://git.kernel.org/stable/c/9154542070ca7eadb3c764a882f39a127677854b"},{"url":"https://git.kernel.org/stable/c/74f577c722c99248d804eca18e7de7c5e47549d7"},{"url":"https://git.kernel.org/stable/c/0af37c217edf15fa21dac1c40822086df356c6bb"}],"title":"btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF","x_generator":{"engine":"bippy-1.2.0"}}}}