PT-2025-49062 · Btrfs+3 · Btrfs+3
Published
2025-10-16
·
Updated
2026-05-07
·
CVE-2025-40235
CVSS v2.0
4.4
Medium
| Vector | AV:L/AC:M/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.15.8
Description
The Linux kernel contains a flaw in the btrfs subsystem where
btrfs check leaked roots() may access a NULL pointer if fs info->super copy or fs info->super for commit allocation fails during btrfs get tree subvol(). This occurs because fs info->allocated roots is not initialized in such cases, leading to a potential crash. The issue was identified through syzkaller testing, which reported a page fault during kernel operation. The vulnerable code resides within the btrfs check leaked roots() function in fs/btrfs/disk-io.c.Recommendations
Upgrade to Linux kernel version 6.15.8 or later.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu
Btrfs