In the Linux kernel, the following vulnerability has been resolved:
btrfs: reject invalid reloc tree root keys with stack dump
[BUG] Syzbot reported a crash that an ASSERT() got triggered inside prepare_to_merge().
That ASSERT() makes sure the reloc tree is properly pointed back by its subvolume tree.
[CAUSE] After more debugging output, it turns out we had an invalid reloc tree:
BTRFS error (device loop1): reloc tree mismatch, root 8 has no reloc root, expect reloc root key (-8, 132, 8) gen 17
Note the above root key is (TREE_RELOC_OBJECTID, ROOT_ITEM, QUOTA_TREE_OBJECTID), meaning it's a reloc tree for quota tree.
But reloc trees can only exist for subvolumes, as for non-subvolume trees, we just COW the involved tree block, no need to create a reloc tree since those tree blocks won't be shared with other trees.
Only subvolumes tree can share tree blocks with other trees (thus they have BTRFS_ROOT_SHAREABLE flag).
Thus this new debug output proves my previous assumption that corrupted on-disk data can trigger that ASSERT().
[FIX] Besides the dedicated fix and the graceful exit, also let tree-checker to check such root keys, to make sure reloc trees can only exist for subvolumes.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade bpftool-debuginfoUpgrade kernelUpgrade kernel-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-headersUpgrade python-perf-debuginfoUpgrade perf-debuginfoUpgrade kernel-tools-debuginfoUpgrade kernel-livepatch-5.15.128-80.144Upgrade kernel-toolsUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-tools-develUpgrade perfUpgrade bpftoolUpgrade kernel-develUpgrade python-perf | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade perfUpgrade kernel-develUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-livepatch-6.1.49-69.116Upgrade python3-perfUpgrade kernel-toolsUpgrade kernel-tools-develUpgrade perf-debuginfoUpgrade kernel-headersUpgrade kernelUpgrade kernel-tools-debuginfoUpgrade kernel-libbpf-staticUpgrade kernel-libbpfUpgrade kernel-libbpf-develUpgrade bpftool-debuginfoUpgrade bpftoolUpgrade kernel-debuginfo-common-x86_64Upgrade python3-perf-debuginfoUpgrade kernel-debuginfo | Oct 24, 2025 | Oct 7, 2025 |
| Debian | — | Upgrade linux | Oct 9, 2025 | Oct 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 7, 2025 |
| Ubuntu | — | Upgrade linux-lowlatency-hwe-5.15Upgrade linux-bluefieldUpgrade linux-nvidia-tegra-5.15Upgrade linux-azureUpgrade linux-gcpUpgrade linux-aws-5.15Upgrade linux-realtimeUpgrade linuxUpgrade linux-awsUpgrade linux-intel-iot-realtimeUpgrade linux-intel-iotg-5.15Upgrade linux-oracle-5.15Upgrade linux-azure-fde-5.15Upgrade linux-kvmUpgrade linux-intel-iotgUpgrade linux-hwe-5.15Upgrade linux-riscv-5.15Upgrade linux-raspiUpgrade linux-nvidiaUpgrade linux-xilinx-zynqmpUpgrade linux-gcp-5.15Upgrade linux-azure-5.15Upgrade linux-lowlatencyUpgrade linux-ibmUpgrade linux-nvidia-tegra-igxUpgrade linux-nvidia-tegraUpgrade linux-gkeUpgrade linux-oracleUpgrade linux-gkeopUpgrade linux-ibm-5.15 | Oct 10, 2025 | Oct 7, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub