CVE-2025-37856

MEDIUM

Linux Kernel < 6.12.24, 6.13.0-6.13.11, 6.14.0-6.14.2 - Use-After-Free in Btrfs Block Group List Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: harden block_group::bg_list against list_del() races As far as I can tell, these calls of list_del_init() on bg_list cannot run concurrently with btrfs_mark_bg_unused() or btrfs_mark_bg_to_reclaim(), as they are in transaction error paths and situations where the block group is readonly. However, if there is any chance at all of racing with mark_bg_unused(), or a different future user of bg_list, better to be safe than sorry. Otherwise we risk the following interleaving (bg_list refcount in parens) T1 (some random op) T2 (btrfs_mark_bg_unused) !list_empty(&bg->bg_list); (1) list_del_init(&bg->bg_list); (1) list_move_tail (1) btrfs_put_block_group (0) btrfs_delete_unused_bgs bg = list_first_entry list_del_init(&bg->bg_list); btrfs_put_block_group(bg); (-1) Ultimately, this results in a broken ref count that hits zero one deref early and the real final deref underflows the refcount, resulting in a WARNING.

Scores

CVSS v3 5.5
EPSS 0.0023
EPSS Percentile 13.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (20)
linux/Kernel 6.13.0 - 6.13.12linux
linux/Kernel 6.14.0 - 6.14.3linux
linux/Kernel 6.5.0 - 6.12.24linux
Linux/Linux < 6.5
Linux/Linux 01eca70ef8cf499d0cb6d1bbd691558e7792cf17
Linux/Linux 5.15.128 - 5.16
Linux/Linux 5d19abcffd8404078dfa7d7118cec357b5e7bc58
Linux/Linux 6.1.47 - 6.2
Linux/Linux 6.12.24 - 6.12.*
Linux/Linux 6.13.12 - 6.13.*
... and 10 more
Published May 09, 2025
Tracked Since Feb 18, 2026