cbcvebase.
CVE-2025-40303
published 2025-12-08

CVE-2025-40303: In the Linux kernel, the following vulnerability has been resolved: btrfs: ensure no dirty metadata is written back for an fs with errors [BUG] During…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.5th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: ensure no dirty metadata is written back for an fs with errors [BUG] During development of a minor feature (make sure all btrfs_bio::end_io() is called in task context), I noticed a crash in generic/388, where metadata writes triggered new works after btrfs_stop_all_workers(). It turns out that it can even happen without any code modification, just using RAID5 for metadata and the same workload from generic/388 is going to trigger the use-after-free. [CAUSE] If btrfs hits an error, the fs is marked as error, no new transaction is allowed thus metadata is in a frozen state. But there are some metadata modifications before that error, and they are still in the btree inode page cache. Since there will be no real transaction commit, all those dirty folios are just kept as is in the page cache, and they can not be invalidated by invalidate_inode_pages2() call inside close_ctree(), because they are dirty. And finally after btrfs_stop_all_workers(), we call iput() on btree inode, which triggers writeback of those dirty metadata. And if the fs is using RAID56 metadata, this will trigger RMW and queue new works into rmw_workers, which is already stopped, causing warning from queue_work() and use-after-free. [FIX] Add a special handling for write_one_eb(), that if the fs is already in an error state, immediately mark the bbio as failure, instead of really submitting them. Then during close_ctree(), iput() will just discard all those dirty tree blocks without really writing them back, thus no more new jobs for already stopped-and-freed workqueues. The extra discard in write_one_eb() also acts as an extra safenet. E.g. the transaction abort is triggered by some extent/free space tree corruptions, and since extent/free space tree is already corrupted some tree blocks may be allocated where they shouldn't be (overwriting existing tree blocks). In that case writing them back will further corrupti

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.8-1 (forky)linux 6.17.8-1 (forky)
linuxlinux
linuxlinux>= 13e6c37b989859e70b0d73d3f2cb0aa022159b17 < 066ee13f05fbd82ada01883e51f0695172f98dff066ee13f05fbd82ada01883e51f0695172f98dff
linuxlinux>= 13e6c37b989859e70b0d73d3f2cb0aa022159b17 < e2b3859067bf012d53c49b3f885fef40624a2c83e2b3859067bf012d53c49b3f885fef40624a2c83
linuxlinux>= 13e6c37b989859e70b0d73d3f2cb0aa022159b17 < 54a5b5a15588e3b0b294df31474d08a2678d429154a5b5a15588e3b0b294df31474d08a2678d4291
linuxlinux>= 13e6c37b989859e70b0d73d3f2cb0aa022159b17 < 2618849f31e7cf51fadd4a5242458501a6d5b3152618849f31e7cf51fadd4a5242458501a6d5b315
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 3.10.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
msrccbl2_libxml2_2.10.3-1_on_cbl_mariner_2.0
msrccm1_libxml2_2.9.14-3_on_cbl_mariner_1.0
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_ubuntu7.8HIGH
vendor_msrc7.5HIGH
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.