PT-2025-49062 · Btrfs+3 · Btrfs+3

Published

2025-10-16

·

Updated

2026-05-07

·

CVE-2025-40235

CVSS v2.0

4.4

Medium

VectorAV:L/AC:M/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.15.8
Description The Linux kernel contains a flaw in the btrfs subsystem where btrfs check leaked roots() may access a NULL pointer if fs info->super copy or fs info->super for commit allocation fails during btrfs get tree subvol(). This occurs because fs info->allocated roots is not initialized in such cases, leading to a potential crash. The issue was identified through syzkaller testing, which reported a page fault during kernel operation. The vulnerable code resides within the btrfs check leaked roots() function in fs/btrfs/disk-io.c.
Recommendations Upgrade to Linux kernel version 6.15.8 or later.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2026-02797
CVE-2025-40235
OPENSUSE-SU-2026:20145-1
SUSE-SU-2026:20207-1
SUSE-SU-2026:20220-1
SUSE-SU-2026:20228-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu
Btrfs