Impact
The vulnerability arises when the Linux kernel’s btrfs subsystem omits an early call to protect folios with an mmap‑ed file to modify sectors while checksumming, compressing, or writing them. This can corrupt checksums, lose writes, alter zeroed bytes past EOF, and produce corrupted compressed data, all of which lead to data integrity failures. The flaw maps to CWE‑413, uninitialized or incorrect data storage.
Affected Systems
The issue exists in all distributions that ship the kernel with btrfs support and have not yet applied the patch. No specific version range is provided, so any kernel containing this code may be affected until a fix is applied.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity. The EPSS score of < 1% reflects a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. Exploitation requires a mapped file undergoing writeback, which typically occurs in privileged services or user data corruption and potential data loss; it does not grant code execution.
OpenCVE Enrichment