CVE-2026-74571
In the Linux kernel, the following vulnerability has been resolved:
btrfs: skip global block reserve accounting for rescue mounts
[BUG] Mounting with rescue=ibadroots after corrupting the block group tree root triggers a NULL pointer dereference:
The same crash occurs with a corrupted raid stripe tree root, via btrfs_read_block_groups() instead of fill_dummy_bgs().
[CAUSE] With rescue=ibadroots, btrfs_read_roots() allows the mount to continue when either root cannot be read, leaving the corresponding root pointer NULL while its on-disk feature bit remains set.
btrfs_update_global_block_rsv() then dereferences the missing root based on the feature bit alone.
Leer descripción completaMostrar menos
[FIX] Rescue mounts are fully read-only and cannot start transactions, so the global reserve is never consumed. Under btrfs_is_full_ro(), mark the reserve as full and return before performing the accounting.
And since we need to check if the fs is mount fully RO, export fs_is_full_ro() as btrfs_is_full_ro(), and move it to fs.h.
[ Squash the fs_is_full_ro() export commit into this one. ]
Detalles técnicos trazas, registros y código del informe original
BUG: kernel NULL pointer dereference, address: 0000000000000100 RIP: 0010:btrfs_update_global_block_rsv+0x9d/0x1c0 [btrfs] Call Trace: fill_dummy_bgs+0xd4/0x120 [btrfs] open_ctree+0xc6e/0x1ca0 [btrfs] btrfs_get_tree+0x50d/0xa40 [btrfs]
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74571",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "8dbfc14fc736eb701089aff09645c3d4ad3decb1",
"lessThan": "076349e4c8d11f6b58c4549976a513b2b4dc6df2",
"versionType": "git"
},
{
"status": "affected",
"version": "8dbfc14fc736eb701089aff09645c3d4ad3decb1",
"lessThan": "51a0e8399858621442807a26057bcd1cd3ced046",
"versionType": "git"
},
{
"status": "affected",
"version": "cbec34d3021d47007a0334c634f7053dbaf93d02",
"versionType": "git"
},
{
"status": "affected",
"version": "1e8087589b5cf6fa17adaf57b64cf1656d77dfec",
"versionType": "git"
},
{
"status": "affected",
"version": "6.1.43",
"lessThan": "6.2",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.4.8",
"lessThan": "6.5",
"versionType": "semver"
}
],
"programFiles": [
"fs/btrfs/block-rsv.c",
"fs/btrfs/disk-io.c",
"fs/btrfs/fs.h"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.5"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.5",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "7.1.8",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/btrfs/block-rsv.c",
"fs/btrfs/disk-io.c",
"fs/btrfs/fs.h"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T13:18:02.733",
"references": [
{
"url": "https://git.kernel.org/stable/c/076349e4c8d11f6b58c4549976a513b2b4dc6df2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/51a0e8399858621442807a26057bcd1cd3ced046",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: skip global block reserve accounting for rescue mounts\n\n[BUG]\nMounting with rescue=ibadroots after corrupting the block group tree\nroot triggers a NULL pointer dereference:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000100\n RIP: 0010:btrfs_update_global_block_rsv+0x9d/0x1c0 [btrfs]\n Call Trace:\n fill_dummy_bgs+0xd4/0x120 [btrfs]\n open_ctree+0xc6e/0x1ca0 [btrfs]\n btrfs_get_tree+0x50d/0xa40 [btrfs]\n\nThe same crash occurs with a corrupted raid stripe tree root, via\nbtrfs_read_block_groups() instead of fill_dummy_bgs().\n\n[CAUSE]\nWith rescue=ibadroots, btrfs_read_roots() allows the mount to continue\nwhen either root cannot be read, leaving the corresponding root pointer\nNULL while its on-disk feature bit remains set.\n\nbtrfs_update_global_block_rsv() then dereferences the missing root based\non the feature bit alone.\n\n[FIX]\nRescue mounts are fully read-only and cannot start transactions, so the\nglobal reserve is never consumed. Under btrfs_is_full_ro(), mark the\nreserve as full and return before performing the accounting.\n\nAnd since we need to check if the fs is mount fully RO, export\nfs_is_full_ro() as btrfs_is_full_ro(), and move it to fs.h.\n\n[ Squash the fs_is_full_ro() export commit into this one. ]"
}
],
"lastModified": "2026-08-17T06:19:55.417",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}