Impact
The Linux kernel’s btrfs file system, when enabled on zoned block devices, incorrectly treated a retryable error code (-EAGAIN) from the block‑group reclaim logic as fatal. This caused btrfs transactions to be aborted, which could leave the file system state inconsistent and potentially corrupt metadata or user data. The defect represents a failure to handle a temporary over‑commit condition properly, leading to loss or corruption of data rather than simply a denial of service.
Affected Systems
All installations of the Linux kernel that execute the pre‑patch btrfs zoned‑storage code are affected. The issue exists in any kernel containing the buggy logic before the patch commit identifiers 8249dfe46337d599e2087b772a2e32ef9f77282b and e549093c11a2fff8430df3dfbdb45eb9811a69a5 are applied. Systems using btrfs on zoned storage devices are the primary targets; other btrfs configurations are not impacted.
Risk and Exploitability
The CVSS score is not provided, but the EPSS score of less than 1% indicates a very low probability of active exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require local access and the ability to trigger a heavy over‑commit condition on a zoned BTRFS filesystem, making the attack surface narrow. Though the impact includes potential loss of data, the overall risk remains low due to the difficulty of exploitation and the lack of public exploits.
OpenCVE Enrichment