Impact
The flaw in the Linux kernel’s btrfs subsystem prevents proper cleanup of relocation root references when a recovery operation aborts. When a relocation recovery exits early because of an error, the code that should drop temporary pointers is bypassed, leaving fs_root structures that still point to relocation roots. These dangling references can trigger a crash or other instability when subsequent filesystem operations use them. The weakness is an example of CWE‑911: Improper Resource Cleanup.
Affected Systems
All Linux kernel implementations that include btrfs support are affected when the missing cleanup logic has not been applied. The specific version range is not listed, so any kernel prior to the patch that added the missing cleanup is susceptible. Mount or format btrfs filesystems may experience the issue.
Risk and Exploitability
The CVSS score of 4.4 reflects moderate severity, largely because the flaw requires the recovery path to be invoked and does not provide an easy remote entry point. The EPSS score of less than 1% indicates that exploitation in the wild is rare. The CVE is not listed in the CISA KEV catalog. Attackers would need to trigger a btrfs relocation recovery—typically by mounting an affected volume or forcing the kernel to recover a corrupt image—which generally requires local privileged execution or a compromised root user. The likely attack vector is thus local privilege escalation or a root‑level action rather than a remote exploit.
OpenCVE Enrichment
Debian DSA