Impact
The vulnerability resides in the btrfs implementation of the Linux kernel. When reading merkle tree pages, the code can find a folio in the mapping that is not marked as up-to-date. The current logic treats that state as a permanent read error and returns -EIO. This means that a transient read failure can become sticky: if a failed read leaves a not‑up‑to‑date folio in the mapping, subsequent callers will encounter the same folio and fail again, preventing the system from recovering by retrying the read. As a result, files or metadata can become inaccessible, potentially leading to data loss or denial of service. The bug does not involve code execution but introduces a significant reliability issue. An attacker who can repeatedly trigger read errors on btrfs data or metadata could cause persistent failure of file access. The weakness is an improper handling of error conditions, leading to denial of service. The vulnerability is fixed by adjusting the read logic to retry merkle item reads when a not‑up‑date folio is encountered and by unlocking the folio on read_key_bytes() failure to allow later retries.
Affected Systems
The issue affects any Linux kernel using the btrfs filesystem that includes the vulnerable module. The vendor list includes Linux:Linux, meaning all community and distribution kernels built with btrfs support. No specific version ranges are listed, so all builds prior to the patch commit are potentially affected.
Risk and Exploitability
The CVSS details are not provided, but the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The attack vector is inferred to be local: a user with read‑access to a btrfs filesystem can trigger the error condition by manipulating file reads. The impact is confined to the affected filesystem; it does not provide remote code execution. Given the low EPSS and lack of external exploitation reports, the immediate risk is moderate if the affected kernel is in use, but can be mitigated by applying the patch promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA