In the Linux kernel, the following vulnerability has been resolved:
btrfs: check folio mapping after unlock in relocate_one_folio()
When we call btrfs_read_folio() to bring a folio uptodate, we unlock the folio. The result of that is that a different thread can modify the mapping (like remove it with invalidate) before we call folio_lock(). This results in an invalid page and we need to try again.
In particular, if we are relocating concurrently with aborting a transaction, this can result in a crash like the following:
BUG: kernel NULL pointer dereference, address: 0000000000000000 PGD 0 P4D 0 Oops: 0000 [#1] SMP CPU: 76 PID: 1411631 Comm: kworker/u322:5 Workqueue: events_unbound btrfs_reclaim_bgs_work RIP: 0010:set_page_extent_mapped+0x20/0xb0 RSP: 0018:ffffc900516a7be8 EFLAGS: 00010246 RAX: ffffea009e851d08 RBX: ffffea009e0b1880 RCX: 0000000000000000 RDX: 0000000000000000 RSI: ffffc900516a7b90 RDI: ffffea009e0b1880 RBP: 0000000003573000 R08: 0000000000000001 R09: ffff88c07fd2f3f0 R10: 0000000000000000 R11: 0000194754b575be R12: 0000000003572000 R13: 0000000003572fff R14: 0000000000100cca R15: 0000000005582fff FS: 0000000000000000(0000) GS:ffff88c07fd00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 0000000000000000 CR3: 000000407d00f002 CR4: 00000000007706f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: <TASK> ? __die+0x78/0xc0 ? page_fault_oops+0x2a8/0x3a0 ? __switch_to+0x133/0x530 ? wq_worker_running+0xa/0x40 ? exc_page_fault+0x63/0x130 ? asm_exc_page_fault+0x22/0x30 ? set_page_extent_mapped+0x20/0xb0 relocate_file_extent_cluster+0x1a7/0x940 relocate_data_extent+0xaf/0x120 relocate_block_group+0x20f/0x480 btrfs_relocate_block_group+0x152/0x320 btrfs_relocate_chunk+0x3d/0x120 btrfs_reclaim_bgs_work+0x2ae/0x4e0 process_scheduled_works+0x184/0x370 worker_thread+0xc6/0x3e0 ? blk_add_timer+0xb0/0xb0 kthread+0xae/0xe0 ? flush_tlb_kernel_range+0x90/0x90 ret_from_fork+0x2f/0x40 ? flush_tlb_kernel_range+0x90/0x90 ret_from_fork_asm+0x11/0x20 </TASK>
This occurs because cleanup_one_transaction() calls destroy_delalloc_inodes() which calls invalidate_inode_pages2() which takes the folio_lock before setting mapping to NULL. We fail to check this, and subsequently call set_extent_mapping(), which assumes that mapping != NULL (in fact it asserts that in debug mode)
Note that the "fixes" patch here is not the one that introduced the race (the very first iteration of this code from 2009) but a more recent change that made this particular crash happen in practice.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel-libbpf-debuginfoUpgrade kernel-tools-develUpgrade kernel-modules-extra-commonUpgrade perf-debuginfoUpgrade kernel-toolsUpgrade kernel-develUpgrade kernel-livepatch-6.1.141-155.222Upgrade kernel-debuginfo-common-aarch64Upgrade kernel-debuginfoUpgrade python3-perfUpgrade perfUpgrade bpftoolUpgrade kernel-tools-debuginfoUpgrade kernel-libbpfUpgrade kernelUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-headersUpgrade python3-perf-debuginfoUpgrade kernel-modules-extraUpgrade kernel-libbpf-develUpgrade bpftool-debuginfoUpgrade kernel-libbpf-static | Jun 24, 2025 | Jan 6, 2025 |
| Debian | — | Upgrade linux-6.1Upgrade linux | May 15, 2025 | Jan 6, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 6, 2025 |
| Ubuntu | — | Upgrade linux-image-oem-22.04Upgrade linux-image-6.11.0-1012-azureUpgrade linux-image-generic-lpaeUpgrade linux-image-oem-24.04bUpgrade linux-image-6.8.0-1028-oemUpgrade linux-image-oem-22.04aUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-6.11.0-1013-oracleUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-6.8.0-1016-azure-nvidiaUpgrade linux-image-6.11.0-1011-lowlatencyUpgrade linux-image-6.8.0-1026-oracleUpgrade linux-image-ibm-classicUpgrade linux-image-azure-fdeUpgrade linux-image-gkeopUpgrade linux-image-6.8.0-1028-nvidiaUpgrade linux-image-6.8.0-1029-azureUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-6.11.0-1011-awsUpgrade linux-image-6.11.0-1007-realtimeUpgrade linux-image-gkeop-6.8Upgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-oem-22.04cUpgrade linux-image-gcp-64k-lts-24.04Upgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-nvidiaUpgrade linux-image-6.11.0-1011-lowlatency-64kUpgrade linux-image-oem-24.04Upgrade linux-image-ibmUpgrade linux-image-6.11.0-21-genericUpgrade linux-image-6.8.0-60-genericUpgrade linux-image-generic-64kUpgrade linux-image-6.8.0-2023-raspi-realtimeUpgrade linux-image-azure-nvidiaUpgrade linux-image-6.8.0-1026-ibmUpgrade linux-image-genericUpgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-oracle-64k-lts-24.04Upgrade linux-image-raspiUpgrade linux-image-azureUpgrade linux-image-lowlatencyUpgrade linux-image-oracle-lts-24.04Upgrade linux-image-6.8.0-1025-gkeUpgrade linux-image-6.8.0-1028-nvidia-64kUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-azure-lts-24.04Upgrade linux-image-lowlatency-64kUpgrade linux-image-6.8.0-1029-awsUpgrade linux-image-gkeUpgrade linux-image-nvidia-6.8Upgrade linux-image-oem-22.04bUpgrade linux-image-6.8.0-1028-raspiUpgrade linux-image-6.8.0-60-generic-64kUpgrade linux-image-gcpUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-nvidia-lowlatencyUpgrade linux-image-6.8.0-60-lowlatencyUpgrade linux-image-realtimeUpgrade linux-image-generic-hwe-22.04Upgrade linux-image-6.8.0-1029-azure-fdeUpgrade linux-image-6.8.0-1026-oracle-64kUpgrade linux-image-6.11.0-1012-azure-fdeUpgrade linux-image-azure-fde-lts-24.04Upgrade linux-image-6.8.0-60-lowlatency-64kUpgrade linux-image-aws-lts-24.04Upgrade linux-image-6.8.0-1012-gkeopUpgrade linux-image-virtualUpgrade linux-image-nvidia-64kUpgrade linux-image-oem-22.04dUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.11.0-21-generic-64kUpgrade linux-image-oem-24.04aUpgrade linux-image-6.11.0-1013-oracle-64kUpgrade linux-image-6.8.0-1028-nvidia-lowlatencyUpgrade linux-image-6.8.0-1030-gcpUpgrade linux-image-kvmUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-gcp-64kUpgrade linux-image-awsUpgrade linux-image-oracleUpgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-6.11.0-1017-oemUpgrade linux-image-oracle-64kUpgrade linux-image-gcp-lts-24.04Upgrade linux-image-raspi-realtimeUpgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-nvidia-64k-6.8Upgrade linux-image-6.11.0-1010-raspiUpgrade linux-image-6.8.0-1028-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1030-gcp-64kUpgrade linux-image-6.11.0-1011-gcp-64kUpgrade linux-image-6.11.0-1011-gcpUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.8.1-1022-realtime | Mar 28, 2025 | Jan 6, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Jan 6, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub