In the Linux kernel, the following vulnerability has been resolved:
btrfs: always detect conflicting inodes when logging inode refs
After rename exchanging (either with the rename exchange operation or regular renames in multiple non-atomic steps) two inodes and at least one of them is a directory, we can end up with a log tree that contains only of the inodes and after a power failure that can result in an attempt to delete the other inode when it should not because it was not deleted before the power failure. In some case that delete attempt fails when the target inode is a directory that contains a subvolume inside it, since the log replay code is not prepared to deal with directory entries that point to root items (only inode items).
1) We have directories "dir1" (inode A) and "dir2" (inode B) under the same parent directory;
2) We have a file (inode C) under directory "dir1" (inode A);
3) We have a subvolume inside directory "dir2" (inode B);
4) All these inodes were persisted in a past transaction and we are currently at transaction N;
5) We rename the file (inode C), so at btrfs_log_new_name() we update inode C's last_unlink_trans to N;
6) We get a rename exchange for "dir1" (inode A) and "dir2" (inode B), so after the exchange "dir1" is inode B and "dir2" is inode A. During the rename exchange we call btrfs_log_new_name() for inodes A and B, but because they are directories, we don't update their last_unlink_trans to N;
7) An fsync against the file (inode C) is done, and because its inode has a last_unlink_trans with a value of N we log its parent directory (inode A) (through btrfs_log_all_parents(), called from btrfs_log_inode_parent()).
8) So we end up with inode B not logged, which now has the old name of inode A. At copy_inode_items_to_log(), when logging inode A, we did not check if we had any conflicting inode to log because inode A has a generation lower than the current transaction (created in a past transaction);
9) After a power failure, when replaying the log tree, since we find that inode A has a new name that conflicts with the name of inode B in the fs tree, we attempt to delete inode B... this is wrong since that directory was never deleted before the power failure, and because there is a subvolume inside that directory, attempting to delete it will fail since replay_dir_deletes() and btrfs_unlink_inode() are not prepared to deal with dir items that point to roots instead of inodes.
When that happens the mount fails and we get a stack trace like the following:
[87.2314] BTRFS info (device dm-0): start tree-log replay [87.2318] BTRFS critical (device dm-0): failed to delete reference to subvol, root 5 inode 256 parent 259 [87.2332] ------------[ cut here ]------------ [87.2338] BTRFS: Transaction aborted (error -2) [87.2346] WARNING: CPU: 1 PID: 638968 at fs/btrfs/inode.c:4345 __btrfs_unlink_inode+0x416/0x440 [btrfs] [87.2368] Modules linked in: btrfs loop dm_thin_pool (...) [87.2470] CPU: 1 UID: 0 PID: 638968 Comm: mount Tainted: G W 6.18.0-rc7-btrfs-next-218+ #2 PREEMPT(full) [87.2489] Tainted: [W]=WARN [87.2494] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014 [87.2514] RIP: 0010:__btrfs_unlink_inode+0x416/0x440 [btrfs] [87.2538] Code: c0 89 04 24 (...) [87.2568] RSP: 0018:ffffc0e741f4b9b8 EFLAGS: 00010286 [87.2574] RAX: 0000000000000000 RBX: ffff9d3ec8a6cf60 RCX: 0000000000000000 [87.2582] RDX: 0000000000000002 RSI: ffffffff84ab45a1 RDI: 00000000ffffffff [87.2591] RBP: ffff9d3ec8a6ef20 R08: 0000000000000000 R09: ffffc0e741f4b840 [87.2599] R10: ffff9d45dc1fffa8 R11: 0000000000000003 R12: ffff9d3ee26d77e0 [87.2608] R13: ffffc0e741f4ba98 R14: ffff9d4458040800 R15: ffff9d44b6b7ca10 [87.2618] FS: 00007f7b9603a840(0000) GS:ffff9d4658982000(0000) knlGS:0000000000000000 [87. ---truncated---
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade perf6.12Upgrade kernel6.12-modules-extra-commonUpgrade kernel6.12-libbpf-staticUpgrade kernel-libbpfUpgrade kernelUpgrade python3-perf6.12-debuginfoUpgrade kernel-debuginfoUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-modules-extra-commonUpgrade kernel-libbpf-develUpgrade kernel-livepatch-6.12.66-88.122Upgrade kernel6.12-libbpfUpgrade python3-perf-debuginfoUpgrade kernel-tools-develUpgrade kernel6.12-tools-develUpgrade kernel-livepatch-6.1.161-183.298Upgrade kernel6.12-tools-debuginfoUpgrade kernel-libbpf-staticUpgrade kernel6.12-debuginfoUpgrade kernel-headersUpgrade kernel6.12-headersUpgrade kernel6.12-libbpf-develUpgrade kernel6.12-toolsUpgrade kernel6.12-debuginfo-common-aarch64Upgrade bpftoolUpgrade kernel6.12-debuginfo-common-x86_64Upgrade python3-perf6.12Upgrade python3-perfUpgrade kernel-tools-debuginfoUpgrade kernel-libbpf-debuginfoUpgrade bpftool-debuginfoUpgrade kernel6.12-libbpf-debuginfoUpgrade kernel6.12-modules-extraUpgrade kernel-modules-extraUpgrade kernel6.12Upgrade bpftool6.12-debuginfoUpgrade kernel-toolsUpgrade kernel-develUpgrade kernel-debuginfo-common-aarch64Upgrade perf-debuginfoUpgrade bpftool6.12Upgrade perfUpgrade kernel6.12-develUpgrade perf6.12-debuginfo | Mar 27, 2026 | Jan 31, 2026 |
| Debian | — | Upgrade linuxUpgrade linux-6.1 | Feb 11, 2026 | Feb 11, 2026 |
| Oracle_linux | — | Upgrade kernel-uek | Mar 12, 2026 | Jan 31, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 31, 2026 |
| Ubuntu | — | Upgrade linux-image-6.17.0-1019-oracleUpgrade linux-image-oracle-6.17Upgrade linux-image-aws-fips-6.8Upgrade linux-image-nvidia-64k-6.8Upgrade linux-image-nvidia-tegra-rtUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-fipsUpgrade linux-image-nvidia-lowlatency-64k-6.8Upgrade linux-image-6.17.0-1031-nvidia-64kUpgrade linux-image-6.8.0-116-fipsUpgrade linux-image-6.8.0-117-genericUpgrade linux-image-gcp-64k-6.17Upgrade linux-image-gcp-fipsUpgrade linux-image-6.17.0-1021-gcpUpgrade linux-image-6.8.0-1058-gcpUpgrade linux-image-gcp-64k-lts-24.04Upgrade linux-image-oracleUpgrade linux-image-6.8.0-1041-gkeopUpgrade linux-image-6.8.0-1054-nvidia-lowlatency-64kUpgrade linux-image-generic-lpaeUpgrade linux-image-oem-24.04cUpgrade linux-image-6.8.0-1058-gcp-64kUpgrade linux-image-6.8.0-117-lowlatencyUpgrade linux-image-nvidia-tegra-rt-6.8Upgrade linux-image-oem-6.17Upgrade linux-image-oracle-64k-6.17Upgrade linux-image-6.8.0-1032-xilinxUpgrade linux-image-oem-24.04bUpgrade linux-image-nvidia-6.8Upgrade linux-image-6.8.0-1055-aws-fipsUpgrade linux-image-aws-fipsUpgrade linux-image-6.8.0-1054-gke-64kUpgrade linux-image-6.8.0-1058-gcp-fipsUpgrade linux-image-aws-64k-6.8Upgrade linux-image-aws-64k-lts-24.04Upgrade linux-image-nvidia-64k-6.17Upgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-6.8.0-1055-ibmUpgrade linux-image-azure-fde-6.17Upgrade linux-image-azure-fipsUpgrade linux-image-kvmUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-lowlatency-64k-6.8Upgrade linux-image-ibm-classicUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-nvidia-6.17Upgrade linux-image-gcp-6.8Upgrade linux-image-azure-fdeUpgrade linux-image-azure-lts-24.04Upgrade linux-image-generic-64k-6.8Upgrade linux-image-gcp-6.17Upgrade linux-image-realtimeUpgrade linux-image-virtualUpgrade linux-image-6.8.0-1059-azureUpgrade linux-image-aws-lts-24.04Upgrade linux-image-gcp-lts-24.04Upgrade linux-image-generic-6.8Upgrade linux-image-gke-64kUpgrade linux-image-ibm-6.8Upgrade linux-image-lowlatency-6.8Upgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1056-raspiUpgrade linux-image-generic-64kUpgrade linux-image-genericUpgrade linux-image-6.8.0-2045-raspi-realtimeUpgrade linux-image-6.8.0-1059-azure-fipsUpgrade linux-image-6.17.0-1018-azure-fdeUpgrade linux-image-raspi-realtimeUpgrade linux-image-oem-24.04Upgrade linux-image-intel-iotgUpgrade linux-image-intel-iot-realtimeUpgrade linux-image-oracle-64kUpgrade linux-image-gkeop-6.8Upgrade linux-image-oem-24.04dUpgrade linux-image-6.17.0-1018-realtimeUpgrade linux-image-gcp-fips-6.8Upgrade linux-image-gcp-64kUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-gcpUpgrade linux-image-azure-fips-6.8Upgrade linux-image-6.8.0-1054-nvidia-64kUpgrade linux-image-raspi-6.8Upgrade linux-image-6.8.0-117-lowlatency-64kUpgrade linux-image-realtime-hwe-24.04Upgrade linux-image-gke-64k-6.8Upgrade linux-image-azure-6.8Upgrade linux-image-6.8.0-1056-azureUpgrade linux-image-realtime-6.17Upgrade linux-image-6.17.0-1021-azureUpgrade linux-image-realtime-hwe-22.04Upgrade linux-image-lowlatency-64kUpgrade linux-image-aws-6.8Upgrade linux-image-oem-24.04aUpgrade linux-image-6.8.0-1055-awsUpgrade linux-image-raspiUpgrade linux-image-nvidia-tegra-6.8Upgrade linux-image-nvidia-lowlatency-6.8Upgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-6.8.0-1055-aws-64kUpgrade linux-image-realtime-6.8.1Upgrade linux-image-6.17.0-1019-oracle-64kUpgrade linux-image-xilinx-zynqmpUpgrade linux-image-nvidia-hwe-24.04Upgrade linux-image-nvidia-64kUpgrade linux-image-xilinx-6.8Upgrade linux-image-gke-6.8Upgrade linux-image-azure-6.17Upgrade linux-image-6.8.1-1051-realtimeUpgrade linux-image-gcp-64k-6.8Upgrade linux-image-gkeopUpgrade linux-image-6.8.0-1054-nvidiaUpgrade linux-image-gkeUpgrade linux-image-6.8.0-1024-nvidia-tegra-rtUpgrade linux-image-6.17.0-1031-nvidiaUpgrade linux-image-6.17.0-1021-gcp-64kUpgrade linux-image-nvidia-64k-hwe-24.04Upgrade linux-image-fips-6.8Upgrade linux-image-6.8.0-1054-nvidia-lowlatencyUpgrade linux-image-6.8.0-1024-nvidia-tegraUpgrade linux-image-6.8.0-1054-gkeUpgrade linux-image-6.17.0-1030-oemUpgrade linux-image-lowlatencyUpgrade linux-image-virtual-6.8Upgrade linux-image-azureUpgrade linux-image-6.8.0-117-generic-64kUpgrade linux-image-xilinxUpgrade linux-image-raspi-realtime-6.8Upgrade linux-image-ibmUpgrade linux-image-nvidia-tegraUpgrade linux-image-nvidia | May 25, 2026 | May 19, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 10, 2026 | Jan 31, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub