Impact
The vulnerability arises from a race condition in the BTRFS filesystem’s ordered‑extent handling. During a direct‑I/O write that finishes short, the inode size is temporarily reverted, causing the kernel to skip waiting for existing ordered extents. If a subsequent buffered write attempts to insert a new ordered extent that overlaps the same range, the btrfs code reaches an assertion failure and the kernel panics. This results in a complete loss of availability for the affected system and requires a reboot to recover.
Affected Systems
The affected systems are Linux kernel releases prior to the commit that enforces unconditional waiting on ordered extents (ff66fe666233). Any kernel that still uses the legacy ordered‑extent logic and mounts BTRFS is vulnerable. Systems running older kernels without this patch, especially those using direct‑I/O on BTRFS, are at risk.
Risk and Exploitability
Based on the description, the likely attack vector is local: an attacker with write access to a BTRFS volume can trigger a kernel panic by performing a direct‑I/O that short‑finishes followed by a buffered write that overlaps the same range. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV database, indicating a low probability of active exploitation. No remote or privilege‑escalation paths are reported. The impact is a denial of service caused by a kernel panic, which may truncate data if the panic occurs during a critical operation, but the primary consequence is loss of service.
OpenCVE Enrichment