Bug 2448690 (CVE-2025-71269)
| Summary: | CVE-2025-71269 kernel: btrfs: do not free data reservation in fallback from inline due to -ENOSPC | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A resource accounting flaw was found in the Linux kernel's btrfs filesystem. When creating an inline extent fails with -ENOSPC, the code falls back to the normal COW (copy-on-write) path. However, it incorrectly frees the reserved qgroup data even though the data will still be written via the fallback path. This causes qgroup accounting to become inconsistent, potentially allowing data writes to exceed quota limits.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-03-18 18:02:34 UTC
|