CVE-2026-45974
Estado: AnalizadaMedia (5.5)—
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found
If btrfs_search_slot_for_read() returns 1, it means we did not find any key greater than or equals to the key we asked for, meaning we have reached the end of the tree and therefore the path is not valid. If this happens we need to break out of the loop and stop, instead of continuing and accessing an invalid path.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
- https://git.kernel.org/stable/c/023545e272f369d487e6a986c1e321c6e04be1da
- https://git.kernel.org/stable/c/0761447f6f51e1c7997960d8e6559337deed6729
- https://git.kernel.org/stable/c/1ee1d006c9fe4d6be5527ab1c84216b80cccbe40
- https://git.kernel.org/stable/c/b2bd557b75b760e4b9d209112bda19314bd64558
- https://git.kernel.org/stable/c/b5b8ade9da452086e78f5d519b90d3769e354853
- https://git.kernel.org/stable/c/d7cf2314dd5e8661c05d076cd627eea9a7f76616
- https://git.kernel.org/stable/c/ecb7c2484cfc83a93658907580035a8adf1e0a92
- https://git.kernel.org/stable/c/fd4913a53e3b54ad7e161847291439fe445d6356
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-45974",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5223cc60b40ae525ae6c94e98824129f1a5b4ae5",
"lessThan": "023545e272f369d487e6a986c1e321c6e04be1da",
"versionType": "git"
},
{
"status": "affected",
"version": "5223cc60b40ae525ae6c94e98824129f1a5b4ae5",
"lessThan": "fd4913a53e3b54ad7e161847291439fe445d6356",
"versionType": "git"
},
{
"status": "affected",
"version": "5223cc60b40ae525ae6c94e98824129f1a5b4ae5",
"lessThan": "b5b8ade9da452086e78f5d519b90d3769e354853",
"versionType": "git"
},
{
"status": "affected",
"version": "5223cc60b40ae525ae6c94e98824129f1a5b4ae5",
"lessThan": "1ee1d006c9fe4d6be5527ab1c84216b80cccbe40",
"versionType": "git"
},
{
"status": "affected",
"version": "5223cc60b40ae525ae6c94e98824129f1a5b4ae5",
"lessThan": "0761447f6f51e1c7997960d8e6559337deed6729",
"versionType": "git"
},
{
"status": "affected",
"version": "5223cc60b40ae525ae6c94e98824129f1a5b4ae5",
"lessThan": "d7cf2314dd5e8661c05d076cd627eea9a7f76616",
"versionType": "git"
},
{
"status": "affected",
"version": "5223cc60b40ae525ae6c94e98824129f1a5b4ae5",
"lessThan": "b2bd557b75b760e4b9d209112bda19314bd64558",
"versionType": "git"
},
{
"status": "affected",
"version": "5223cc60b40ae525ae6c94e98824129f1a5b4ae5",
"lessThan": "ecb7c2484cfc83a93658907580035a8adf1e0a92",
"versionType": "git"
},
{
"status": "affected",
"version": "ecce1be9f2a366990d0e75dd249fb324e83c34a9",
"versionType": "git"
},
{
"status": "affected",
"version": "5.9.7",
"lessThan": "5.10",
"versionType": "semver"
}
],
"programFiles": [
"fs/btrfs/qgroup.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.252",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.202",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.165",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.128",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.14",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver",
"lessThanOrEqual": "6.19.*"
},
{
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/btrfs/qgroup.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-05-27T14:17:14.430",
"references": [
{
"url": "https://git.kernel.org/stable/c/023545e272f369d487e6a986c1e321c6e04be1da",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/0761447f6f51e1c7997960d8e6559337deed6729",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1ee1d006c9fe4d6be5527ab1c84216b80cccbe40",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b2bd557b75b760e4b9d209112bda19314bd64558",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b5b8ade9da452086e78f5d519b90d3769e354853",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d7cf2314dd5e8661c05d076cd627eea9a7f76616",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ecb7c2484cfc83a93658907580035a8adf1e0a92",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fd4913a53e3b54ad7e161847291439fe445d6356",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found\n\nIf btrfs_search_slot_for_read() returns 1, it means we did not find any\nkey greater than or equals to the key we asked for, meaning we have\nreached the end of the tree and therefore the path is not valid. If\nthis happens we need to break out of the loop and stop, instead of\ncontinuing and accessing an invalid path."
}
],
"lastModified": "2026-06-17T10:52:49.727",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41953BA2-2A4C-4534-B159-A460A8F0E834",
"versionEndExcluding": "5.10",
"versionStartIncluding": "5.9.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F24343B2-B24A-4AD6-8594-17FCDB3549F4",
"versionEndExcluding": "5.10.252",
"versionStartIncluding": "5.10.1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4002FC2B-1456-4666-B240-0EBF590C4671",
"versionEndExcluding": "5.15.202",
"versionStartIncluding": "5.11"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "797C7F46-D0BE-4FB8-A502-C5EF8E6B6654",
"versionEndExcluding": "6.1.165",
"versionStartIncluding": "5.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "851E9353-6C09-4CC9-877E-E09DB164A3C2",
"versionEndExcluding": "6.6.128",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCE16369-98ED-41CF-8995-DFDC10B288D2",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF463CB7-1F58-4607-B847-77ED23E4B9B7",
"versionEndExcluding": "6.18.14",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "672A3E79-EC03-479D-8503-361DFBDC8092",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "6.19"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.10:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B29EBB93-107F-4ED6-8DE3-C2732BC659C3"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.10:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12505363-342C-4333-98C0-41F031024348"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.10:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8F48621E-C427-4C23-9EA6-894419841360"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.10:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0CD159FA-170F-4389-9085-CACCF97ABB1E"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.10:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F0390D83-6C17-4557-BE8D-B659E04F565A"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.10:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4120E4B3-B66D-4ACE-8570-1DD4DF20A324"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:5.10:rc7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73D60343-647D-4B5D-AA6D-CE87C462E368"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}