CVE-2026-74321
CVE CVE-2026-74321EUVD EUVD-2026-59468Published 2026-08-15T05:58:17.000ZLast changed 2026-08-17T05:45:52.000ZCVSS 7.5
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() In the beginning of the loop, we try to obtain a locked delayed ref head, if 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(), which can return an error pointer. If the error pointer is -EAGAIN we do a continue and go back to the beginning of the loop, which will not try again to call btrfs_select_ref_head() since 'locked_ref' is no longer NULL but it's ERR_PTR(-EAGAIN), and then we do: spin_lock(&locked_ref->lock); against a ERR_PTR(-EAGAIN) value, generating an invalid pointer dereference. Fix this by ensuring that 'locked_ref' is set to NULL when btrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count' as well, to prevent infinite looping. We do this by doing a goto to the bottom of the loop that already sets 'locked_ref' to NULL and does a cond_resched(), with an increment to 'count' right before the goto. These measures were in place before the refactoring in commit 0110a4c43451 ("btrfs: refactor __btrfs_run_delayed_refs loop") but were unintentionally lost afterwards.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 6.12.97; patch: 6.1.178; 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 <65770111a2d47c2b15e20b2ba92bb12198f289d4; patch: 6.6.145; 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 <a71143590ce9764dbcb47617647592ff8b4d48bc; 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 <9faa6b69ad73f03c7bde53e07d75a28822dc9a1a; 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 <3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1; patch: 7.1.5; 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 <c372ca227e16bace86f1df1fa4ae6849e2fcfa28; patch: 5.15.212; 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 <ba9fa2ff5981589bb49094d3358c339b37c47f53; patch: 6.18.40; 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 <015dc4a1e0c2cba551d4620eba13d26d5081dc34; patch: 0; 0110a4c43451533de1ea1bbdc57b5d452f9d8b25 <486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae; 4.20; patch: 5.10.261; patch: 7.2
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.