{"api_version":"1","generated_at":"2026-10-01T19:08:53+00:00","cve":"CVE-2026-97415","urls":{"html":"https://cve.report/CVE-2026-97415","api":"https://cve.report/api/cve/CVE-2026-97415.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-97415","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-97415"},"summary":{"title":"btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF\n\nROOT_REF and ROOT_BACKREF items contain a struct btrfs_root_ref followed\nby the subvolume name. Several readers assume that this layout is already\nvalid and then use the on-disk name length directly. A corrupted item can\ntherefore make those readers address bytes outside the item, and\nBTRFS_IOC_GET_SUBVOL_INFO can copy too many bytes into its fixed-size UAPI\nname buffer.\n\nValidate ROOT_REF and ROOT_BACKREF items in tree-checker before any reader\nuses them. Reject records that do not contain a non-empty name, whose\nname_len does not exactly describe the remaining item payload, or whose\nname exceeds BTRFS_NAME_LEN.\n\nFor BTRFS_IOC_GET_SUBVOL_INFO, copy only the validated on-disk name_len\ninstead of deriving the copy length from the item size. The ioctl result is\nzeroed when allocated. That leaves the existing trailing zero byte\nuntouched.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 17:17:19","updated_at":"2026-09-25 13:17:25"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/0af37c217edf15fa21dac1c40822086df356c6bb","name":"https://git.kernel.org/stable/c/0af37c217edf15fa21dac1c40822086df356c6bb","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/74f577c722c99248d804eca18e7de7c5e47549d7","name":"https://git.kernel.org/stable/c/74f577c722c99248d804eca18e7de7c5e47549d7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/9154542070ca7eadb3c764a882f39a127677854b","name":"https://git.kernel.org/stable/c/9154542070ca7eadb3c764a882f39a127677854b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-97415","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-97415","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2ede0daf01549cecf4bb0962c46dc47382047523 9154542070ca7eadb3c764a882f39a127677854b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2ede0daf01549cecf4bb0962c46dc47382047523 74f577c722c99248d804eca18e7de7c5e47549d7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2ede0daf01549cecf4bb0962c46dc47382047523 0af37c217edf15fa21dac1c40822086df356c6bb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 2.6.37","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 2.6.37 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"97415","cve":"CVE-2026-97415","epss":"0.001300000","percentile":"0.021770000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/btrfs/ioctl.c","fs/btrfs/tree-checker.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"9154542070ca7eadb3c764a882f39a127677854b","status":"affected","version":"2ede0daf01549cecf4bb0962c46dc47382047523","versionType":"git"},{"lessThan":"74f577c722c99248d804eca18e7de7c5e47549d7","status":"affected","version":"2ede0daf01549cecf4bb0962c46dc47382047523","versionType":"git"},{"lessThan":"0af37c217edf15fa21dac1c40822086df356c6bb","status":"affected","version":"2ede0daf01549cecf4bb0962c46dc47382047523","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/btrfs/ioctl.c","fs/btrfs/tree-checker.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"2.6.37"},{"lessThan":"2.6.37","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","versionStartIncluding":"2.6.37","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","versionStartIncluding":"2.6.37","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"2.6.37","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF\n\nROOT_REF and ROOT_BACKREF items contain a struct btrfs_root_ref followed\nby the subvolume name. Several readers assume that this layout is already\nvalid and then use the on-disk name length directly. A corrupted item can\ntherefore make those readers address bytes outside the item, and\nBTRFS_IOC_GET_SUBVOL_INFO can copy too many bytes into its fixed-size UAPI\nname buffer.\n\nValidate ROOT_REF and ROOT_BACKREF items in tree-checker before any reader\nuses them. Reject records that do not contain a non-empty name, whose\nname_len does not exactly describe the remaining item payload, or whose\nname exceeds BTRFS_NAME_LEN.\n\nFor BTRFS_IOC_GET_SUBVOL_INFO, copy only the validated on-disk name_len\ninstead of deriving the copy length from the item size. The ioctl result is\nzeroed when allocated. That leaves the existing trailing zero byte\nuntouched."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - The attacker-controlled bytes are the on-disk BTRFS_ROOT_BACKREF_KEY item (struct btrfs_root_ref plus the following name) in the tree of tree roots. After that image is mounted, ioctl(BTRFS_IOC_GET_SUBVOL_INFO) reaches _btrfs_ioctl_get_subvol_info() via btrfs_ioctl() and read_extent_buffer()s the item; no SMB/NFS/packet field carries that payload.\nAC:L - check_leaf_item() had no BTRFS_ROOT_REF_KEY/BTRFS_ROOT_BACKREF_KEY case, so btrfs_check_leaf() accepted a ROOT_BACKREF whose item_size filled the leaf (~BTRFS_LEAF_DATA_SIZE). _btrfs_ioctl_get_subvol_info() then copied item_size-sizeof(struct btrfs_root_ref) into name[256] on every ioctl; the attacker fully controls that image.\nPR:L - btrfs_ioctl() dispatches BTRFS_IOC_GET_SUBVOL_INFO and BTRFS_IOC_INO_LOOKUP_USER with no capable() check. btrfs_fs_type has no FS_USERNS_MOUNT, so the severe case is an unprivileged session user whose USB/loop btrfs image is mounted by udisks2/polkit, then opens any fd in that subvolume and issues the ioctl.\nUI:N - The attacker crafts the ROOT_BACKREF, has that local image mounted, and themselves calls BTRFS_IOC_GET_SUBVOL_INFO (or BTRFS_IOC_INO_LOOKUP_USER, which copies the same item via btrfs_search_path_in_tree_user()) on their own fd. Automount of that local/removable image is not a separate victim action once AV is Local.\nS:U - The overflow is in the host kernel's kzalloc'd btrfs_ioctl_get_subvol_info_args (and ino_lookup_user args) while parsing tree_root ROOT_BACKREF/ROOT_REF items. No KVM/Xen guest-to-host, IOMMU, or sandbox boundary is crossed.\nC:H - _btrfs_ioctl_get_subvol_info() and btrfs_search_path_in_tree_user() call read_extent_buffer() with a length taken from the on-disk item_size into name[BTRFS_VOL_NAME_MAX+1] (256 bytes). That out-of-bounds write of attacker-chosen leaf bytes into adjacent slab is a kernel-memory disclosure primitive.\nI:H - The same unbounded read_extent_buffer() into the 256-byte name[] of the kzalloc'd ioctl args overwrites neighboring heap objects with attacker-controlled ROOT_BACKREF payload, which is sufficient for an arbitrary kernel write and control-flow hijacking.\nA:H - Copying a leaf-sized ROOT_BACKREF past btrfs_ioctl_get_subvol_info_args.name[256], or writing args->name[item_len]='\\0' in btrfs_search_path_in_tree_user() with that huge item_len, oopses or panics the kernel on the slab out-of-bounds access."}]}],"providerMetadata":{"dateUpdated":"2026-09-25T12:43:50.260Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/9154542070ca7eadb3c764a882f39a127677854b"},{"url":"https://git.kernel.org/stable/c/74f577c722c99248d804eca18e7de7c5e47549d7"},{"url":"https://git.kernel.org/stable/c/0af37c217edf15fa21dac1c40822086df356c6bb"}],"title":"btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-97415","datePublished":"2026-09-24T16:03:22.780Z","dateReserved":"2026-09-24T14:53:16.867Z","dateUpdated":"2026-09-25T12:43:50.260Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 17:17:19","lastModifiedDate":"2026-09-25 13:17:25","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"97415","Ordinal":"1","Title":"btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF","CVE":"CVE-2026-97415","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"97415","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF\n\nROOT_REF and ROOT_BACKREF items contain a struct btrfs_root_ref followed\nby the subvolume name. Several readers assume that this layout is already\nvalid and then use the on-disk name length directly. A corrupted item can\ntherefore make those readers address bytes outside the item, and\nBTRFS_IOC_GET_SUBVOL_INFO can copy too many bytes into its fixed-size UAPI\nname buffer.\n\nValidate ROOT_REF and ROOT_BACKREF items in tree-checker before any reader\nuses them. Reject records that do not contain a non-empty name, whose\nname_len does not exactly describe the remaining item payload, or whose\nname exceeds BTRFS_NAME_LEN.\n\nFor BTRFS_IOC_GET_SUBVOL_INFO, copy only the validated on-disk name_len\ninstead of deriving the copy length from the item size. The ioctl result is\nzeroed when allocated. That leaves the existing trailing zero byte\nuntouched.","Type":"Description","Title":"btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF"}]}}}