CVE-2026-74321
btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
Description
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() In the beginning of the loop, we try to obtain a locked delayed ref head, if 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(), which can return an error pointer. If the error pointer is -EAGAIN we do a continue and go back to the beginning of the loop, which will not try again to call btrfs_select_ref_head() since 'locked_ref' is no longer NULL but it's ERR_PTR(-EAGAIN), and then we do: spin_lock(&locked_ref->lock); against a ERR_PTR(-EAGAIN) value, generating an invalid pointer dereference. Fix this by ensuring that 'locked_ref' is set to NULL when btrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count' as well, to prevent infinite looping. We do this by doing a goto to the bottom of the loop that already sets 'locked_ref' to NULL and does a cond_resched(), with an increment to 'count' right before the goto. These measures were in place before the refactoring in commit 0110a4c43451 ("btrfs: refactor __btrfs_run_delayed_refs loop") but were unintentionally lost afterwards.
INFO
Published Date :
Aug. 15, 2026, 6:22 a.m.
Last Modified :
Aug. 17, 2026, 6:19 a.m.
Remotely Exploit :
Yes !
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Update the Linux kernel to the patched version.
- Recompile the kernel if necessary.
- Deploy the updated kernel to affected systems.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-74321.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-74321 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-74321
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-74321 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-74321 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': 'c372ca227e16bace86f1df1fa4ae6849e2fcfa28', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': 'a71143590ce9764dbcb47617647592ff8b4d48bc', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '65770111a2d47c2b15e20b2ba92bb12198f289d4', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '015dc4a1e0c2cba551d4620eba13d26d5081dc34', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': 'ba9fa2ff5981589bb49094d3358c339b37c47f53', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '9faa6b69ad73f03c7bde53e07d75a28822dc9a1a', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae', 'versionType': 'git'}], 'programFiles': ['fs/btrfs/extent-tree.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.20'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.20', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/btrfs/extent-tree.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': 'c372ca227e16bace86f1df1fa4ae6849e2fcfa28', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': 'a71143590ce9764dbcb47617647592ff8b4d48bc', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '65770111a2d47c2b15e20b2ba92bb12198f289d4', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '015dc4a1e0c2cba551d4620eba13d26d5081dc34', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': 'ba9fa2ff5981589bb49094d3358c339b37c47f53', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '9faa6b69ad73f03c7bde53e07d75a28822dc9a1a', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae', 'versionType': 'git'}], 'programFiles': ['fs/btrfs/extent-tree.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.20'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.20', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/btrfs/extent-tree.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 15, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': 'c372ca227e16bace86f1df1fa4ae6849e2fcfa28', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': 'a71143590ce9764dbcb47617647592ff8b4d48bc', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '65770111a2d47c2b15e20b2ba92bb12198f289d4', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '015dc4a1e0c2cba551d4620eba13d26d5081dc34', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': 'ba9fa2ff5981589bb49094d3358c339b37c47f53', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '9faa6b69ad73f03c7bde53e07d75a28822dc9a1a', 'versionType': 'git'}, {'status': 'affected', 'version': '0110a4c43451533de1ea1bbdc57b5d452f9d8b25', 'lessThan': '486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae', 'versionType': 'git'}], 'programFiles': ['fs/btrfs/extent-tree.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '4.20'}, {'status': 'unaffected', 'version': '0', 'lessThan': '4.20', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.261', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.212', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['fs/btrfs/extent-tree.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() In the beginning of the loop, we try to obtain a locked delayed ref head, if 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(), which can return an error pointer. If the error pointer is -EAGAIN we do a continue and go back to the beginning of the loop, which will not try again to call btrfs_select_ref_head() since 'locked_ref' is no longer NULL but it's ERR_PTR(-EAGAIN), and then we do: spin_lock(&locked_ref->lock); against a ERR_PTR(-EAGAIN) value, generating an invalid pointer dereference. Fix this by ensuring that 'locked_ref' is set to NULL when btrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count' as well, to prevent infinite looping. We do this by doing a goto to the bottom of the loop that already sets 'locked_ref' to NULL and does a cond_resched(), with an increment to 'count' right before the goto. These measures were in place before the refactoring in commit 0110a4c43451 ("btrfs: refactor __btrfs_run_delayed_refs loop") but were unintentionally lost afterwards. Added Reference https://git.kernel.org/stable/c/015dc4a1e0c2cba551d4620eba13d26d5081dc34 Added Reference https://git.kernel.org/stable/c/3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1 Added Reference https://git.kernel.org/stable/c/486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae Added Reference https://git.kernel.org/stable/c/65770111a2d47c2b15e20b2ba92bb12198f289d4 Added Reference https://git.kernel.org/stable/c/9faa6b69ad73f03c7bde53e07d75a28822dc9a1a Added Reference https://git.kernel.org/stable/c/a71143590ce9764dbcb47617647592ff8b4d48bc Added Reference https://git.kernel.org/stable/c/ba9fa2ff5981589bb49094d3358c339b37c47f53 Added Reference https://git.kernel.org/stable/c/c372ca227e16bace86f1df1fa4ae6849e2fcfa28