İçeriğe atla
Noroxi
CVE-2026-89772· NVD / CVE Programı· CNA Linux

btrfs: write-protect folios during data writeback

In the Linux kernel, the following vulnerability has been resolved: btrfs: write-protect folios during data writeback commit 095be159f3eb ("btrfs: unify folio dirty flag clearing") replaced the folio_clear_dirty_for_io() call in extent_write_cache_pages() with a plain folio_test_dirty() check. Besides clearing the dirty flag, folio_clear_dirty_for_io() also calls folio_mkclean(), which write-protects the shared mmap PTEs mapping the folio. Note that we still do call folio_clear_dirty_for_io() later in submit_one_sector() when we clear dirty on the last sector of the folio (the only sector for non-subpage cases). But we lost this early call in extent_write_cache_pages(). Without the extra write-protection, a process with the file mmap-ed can modify a sector while it is being used by writeback in a way that expects a stable folio (checksumming, compressing, copying, etc...) without faulting, which manifests as a handful of concrete bugs. 1. For large folios or subpage sectorsize, it is possible to submit a bio which does not cover the whole folio. When this happens, we will have a bio in flight for a folio that we have *not* called folio_clear_dirty_for_io() on. If a task with an existing mmap-ed PTE writes (without faulting..) in this window, it can result in corruptions. If the write arrives while the checksumming or writing itself is underway, this can result in an invalid checksum and later corruption reports on read. If the write arrives after checksumming/writing is done but before the last sector dirty is cleared, then the write is present in page cache but doesn't affect the dirty tracking and will be lost when the folio is fully finished being submitted and the dirty bit is cleared. This results in losing the write even if fsync() is called. 2. For zoned submissions which are done in batch separate from the main extent_writepage() loop, we also risk csum violations for those submissions. Zoned writes are clamped to max_zone_append_size and are not aligned with folios, so a submission can span two folios. The first folio being processed in extent_write_cache_pages() will call extent_write_locked_range() which will submit the partial range of the next folio, while the rest of that folio could still be dirty. So clearing dirty on the submitted sectors doesn't call folio_clear_dirty_for_io() and we have the same issue. Since extent_write_cache_pages() skips these batch submitted folios (they are already marked for writeback from submission by the preceding folio), we must add the extra write protection in lock_delalloc_folios(). 3. For inline extents this will subtly risk losing writes that happen after/while we copy the inline extent but before we clear dirty on the folio. 4. For folios spanning EOF, mmap could tamper with the zeroed bytes past EOF and cause them to be persisted where future faults would improperly see them instead of zeros. 5. Finally, for compressed extents, we risk modifying the folios while we work on compressing them which will result in corrupted compressed data. Specifically, in run_delalloc_compressed() we queue up work to do compress_file_range() in BTRFS_COMPRESSION_CHUNK_SIZE (512K) chunks which will call btrfs_folio_clamp_clear_dirty() on the range. For non-subpage, this will always clear the whole folio, safely. For subpage, we risk a partial clear here as well. In particular, imagine a 2M folio broken up into 512K chunks of work which might start compression work on one chunk before all the chunks compress_file_range() workers have gotten far enough to finish clearing all the dirty bitmaps of the folio and getting to folio_clear_dirty_for_io(). Large folios on the edges of submission ranges are similarly at risk to be only partly cleared. This particular gap was introduced by a second patch in the same series: commit a4ef54dbb576 ("btrfs: make extent_range_clear_dirty_for_io() to handle sector size < page size cases") We cannot simply restore the call to folio_clear ---truncated---

—İstismar yok Düzeltme var
Yayın
11 Eyl 2026
Güncelleme
11 Eyl 2026
EPSS
%0,2 · 9. yüzdelik
CWE
—
Bu CVE’yi takip et

Takip etmek için giriş yap · Takip ettiğin kayıt KEV’e girer, istismarı çıkar ya da güncellenirse bildirim alırsın.

Rapor araçları

JSON

Aksiyon skoru

0

İzleyin

Şimdilik düşük öncelik.

CVSS
0 / 40 · —
CISA KEV
0 / 30 · Listede değil
EPSS
0 / 30 · %0,2

Noroxi analizi

Bu kayıt için henüz Noroxi analizi yok

Veritabanındaki yüz binlerce zafiyetin tamamına elle analiz yazmıyoruz; bu dürüst olmazdı. Öne çıkan ve sahada etkisi olan zafiyetler için mekanizma, tespit ve kapatma adımlarını ekibimiz yazıyor.

Bu ürünü kullanıyoruz, yardım isteyin

Etkilenen sistemler

—

Üreticinin bildirdiği sürümler

Kaydı açan otorite (Linux) tarafından bildirilen etkilenen sürüm aralıkları. NVD'nin CPE analizinden bağımsızdır ve genellikle ondan önce gelir.

  • Linux Linux

    • 6.13etkilenir
    • a4ef54dbb576032ba31a646a5ffc8a26a83cb92c ve sonrası · 074c715e0b498891c09fe7f11e1cd9d7a04699bd öncesietkilenir · git
    • a4ef54dbb576032ba31a646a5ffc8a26a83cb92c ve sonrası · 5376c9db45368eb210b4d71104ac00a59dc8b6e0 öncesietkilenir · git
    • 6.13 öncesietkilenmez · semver
    • 7.2.4 ve sonrası · 7.2.* dahil öncesietkilenmez · semver
    • 7.3-rc1 ve sonrasıetkilenmez · original_commit_for_fix

Paket düzeyi etkilenme

OSV ve GitHub Advisory verisi: ekosistem, paket ve aralık. SBOM eşleşmesi bu tabloyu kullanır.

EkosistemPaketEtkilenen aralıkDüzeltme
Debian:14linux7.2.6-1 öncesi7.2.6-1

Aynı birincil ürünün en yüksek skorlu diğer kayıtları.

  • CVE-2026-74705udp: fix potential use-after-free in tunnel segmentation
    40Planlayın
  • CVE-2026-74612veth: fix skb length accounting after XDP frag adjustment
    40Planlayın
  • CVE-2026-74475vxlan: use neigh_ha_snapshot() in route_shortcircuit()
    40Planlayın
  • CVE-2026-74309vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
    40Planlayın
  • CVE-2026-74280crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
    40Planlayın
  • CVE-2026-74279crypto: cavium/cpt - fix DMA cleanup using wrong loop index
    40Planlayın

Düzeltme

Hangi sürüme geçmeli

Üretici, paket deposu ve Microsoft kayıtlarından derlenen düzeltme sürümleri. Yükseltmeden önce üreticinin notunu doğrulayın.

Ürün / paketDüzeltilmiş sürümKaynak
Linux Linux074c715e0b498891c09fe7f11e1cd9d7a04699bdÜretici (CNA)
Linux Linux5376c9db45368eb210b4d71104ac00a59dc8b6e0Üretici (CNA)
debian:linux7.2.6-1 · Debian:14Paket deposu (OSV)

İstismar durumu

Bilinen kamuya açık istismar yok

Şu an kamuya açık bir istismar görülmedi. Bu, güvende olduğunuz anlamına gelmez; yalnızca eşiğin biraz daha yüksek olduğunu gösterir.

Araştırma bağlamı

Pentester ve araştırmacı için: saldırı profili, puan anlaşmazlığı, zaman çizelgesi, yama commit’leri, kredi, varyant ve zincir adayları, bug bounty kapsamı. Hepsi mevcut veriden türetilir; istismar kodu içermez.

Zaman çizelgesi

Yayından bugüne: kavram kanıtı, Metasploit modülü, CISA KEV ve düzeltme kaydı. Tarihler kaynakların bildirdiği tarihlerdir.

Yayın dışında tarihli olay yok.

EPSS son 120 gün

FIRST EPSS günlük puanı; yalnızca 0,01 ve üstü değişimler kaydedilir (adım grafiği).

Yama ve commit bağlantıları

Referanslardaki commit, PR ve diff adresleri. Patch-diff ve varyant avı için başlangıç noktası; istismar değil, düzeltmedir.

Referanslarda commit ya da PR bağlantısı yok.

CNA kaydında adı geçen bulan, bildiren ve analistler. Ada tıkla, aynı araştırmacının diğer kayıtlarını gör.

CNA kaydında kredi yok.

Varyant adayları

Aynı üründe aynı zafiyet sınıfı, 18 ay içinde. Yama kök nedeni kapatmadıysa kardeş hata burada olur.

Gece hesaplanan ilişki yok.

Zincir adayları

Aynı üründe kimlik doğrulama atlatma ile yetki isteyen bir açık kısa aralıkla yayımlanmış: birlikte kimlik doğrulamasız bir yola dönüşebilir.

—

Bug bounty kapsamı

Bilinen herkese açık program yok.

Kaynak: bounty-targets-data (HackerOne, Bugcrowd, Intigriti, YesWeHack herkese açık listeleri).

Ulusal bildirim (Siber Güvenlik Başkanlığı / USOM)

Bu kaydı anan resmi güvenlik bildirimleri; çözüm önerisi kurumun sayfasında.

Tüm ulusal bildirimler →

Teknik detay

Bu kayıt için CVSS vektörü yok; saldırı koşulları çıkarılamıyor.

Zayıflık sınıfı (CWE)

—

Saldırı bağlamı

Bu zafiyet sınıfının (CWE) MITRE CAPEC saldırı desenleri ve ATT&CK teknikleri. Tespit kuralı ve tehdit avı için başlangıç noktası.

Bu CWE için MITRE'de CAPEC/ATT&CK eşlemesi yok.

Değişiklik günlüğü

  1. Düzeltme✗ → ✓

Takip ettiğiniz kayıtlarda bu değişiklikler bildirim olarak da gelir. →

Referanslar

Üretici bildirimleri ve resmî kayıtlar. İstismar/PoC bağlantıları bilinçli olarak dışarıda bırakıldı.

Tüm kayıtlar