CVE-2026-74321

Source
https://cve.org/CVERecord?id=CVE-2026-74321
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74321.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74321
Downstream
Published
2026-08-15T05:58:17.485Z
Modified
2026-08-16T03:48:34.806764231Z
Summary
btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
Details

In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix invalid pointer dereference in _btrfsrundelayedrefs()

In the beginning of the loop, we try to obtain a locked delayed ref head, if 'lockedref' is currently NULL, by calling btrfsselectrefhead(), which can return an error pointer. If the error pointer is -EAGAIN we do a continue and go back to the beginning of the loop, which will not try again to call btrfsselectrefhead() since 'lockedref' is no longer NULL but it's ERR_PTR(-EAGAIN), and then we do:

spinlock(&lockedref->lock);

against a ERR_PTR(-EAGAIN) value, generating an invalid pointer dereference.

Fix this by ensuring that 'lockedref' is set to NULL when btrfsselectrefhead() returns ERRPTR(-EAGAIN) and incrementing 'count' as well, to prevent infinite looping. We do this by doing a goto to the bottom of the loop that already sets 'lockedref' to NULL and does a cond_resched(), with an increment to 'count' right before the goto. These measures were in place before the refactoring in commit 0110a4c43451 ("btrfs: refactor _btrfsrundelayedrefs loop") but were unintentionally lost afterwards.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74321.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0110a4c43451533de1ea1bbdc57b5d452f9d8b25
Fixed
c372ca227e16bace86f1df1fa4ae6849e2fcfa28
Fixed
a71143590ce9764dbcb47617647592ff8b4d48bc
Fixed
65770111a2d47c2b15e20b2ba92bb12198f289d4
Fixed
015dc4a1e0c2cba551d4620eba13d26d5081dc34
Fixed
ba9fa2ff5981589bb49094d3358c339b37c47f53
Fixed
3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1
Fixed
9faa6b69ad73f03c7bde53e07d75a28822dc9a1a
Fixed
486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74321.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74321.json"