Impact
In the Linux kernel, a defect in the BTRFS implementation for zoned storage causes the extent buffer to be cleared with a memzero operation while freeing a tree block. Because the buffer may still be referenced by cleanup code, the in‑memory header is destroyed. The subsequent call to btrfs_free_tree_block reads the zeroed header, corrupting the extent tree or triggering an assertion and aborting the kernel. The result is a kernel panic or corruption of the BTRFS filesystem, potentially leading to data loss or a denial of service.
Affected Systems
All Linux kernel releases that include unpatched BTRFS zoned code and are configured with zoned support are vulnerable. The vulnerability applies to any system using BTRFS on a zoned storage device, but specific version or distribution information is not provided.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity. The EPSS score of less than 1 % shows a low likelihood of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. It does not provide direct code execution; instead, it can lead to kernel crashes and filesystem corruption when the patched BTRFS zoned path is executed during normal operation.
OpenCVE Enrichment