PT-2025-28989 · Btrfs+5 · Btrfs+5

Anubis

·

Published

2025-04-10

·

Updated

2026-04-20

·

CVE-2025-38269

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: In the Linux kernel, a flaw exists within the btrfs subsystem, specifically in the btrfs convert extent bit() function. If the insert state() function fails, it returns an error pointer. Subsequently, extent io tree panic() is called, which triggers a BUG() call. However, if CONFIG BUG is disabled—an uncommon configuration—execution continues to cache state(), leading to a dereference of the error pointer and resulting in an invalid memory access.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

AZL-65004
AZL-70651
BDU:2025-10313
CVE-2025-38269
ECHO-280C-239A-E0C1
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7789-1
USN-7789-2
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Ubuntu
Btrfs