cbcvebase.
CVE-2026-46251
published 2026-06-03

CVE-2026-46251: In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dirty_list corruption When the incompat flag EXTENT_TREE_V2 is…

PriorityP340high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.13%
3.1th percentile
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dirty_list corruption When the incompat flag EXTENT_TREE_V2 is set, we unconditionally add the block group tree to the switch_commits list before calling switch_commit_roots, as we do for the tree root and the chunk root. However, the block group tree uses normal root dirty tracking and in any transaction that does an allocation and dirties a block group, the block group root will already be linked to a list by the dirty_list field and this use of list_add_tail() is invalid and corrupts the prev/next members of block_group_root->dirty_list. This is apparent on a subsequent list_del on the prev if we enable CONFIG_DEBUG_LIST: [32.1571] ------------[ cut here ]------------ [32.1572] list_del corruption. next->prev should beffff958890202538, but was ffff9588992bd538. (next=ffff958890201538) [32.1575] WARNING: lib/list_debug.c:65 at 0x0, CPU#3: sync/607 [32.1583] CPU: 3 UID: 0 PID: 607 Comm: sync Not tainted 6.18.0 #24PREEMPT(none) [32.1585] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS1.17.0-4.fc41 04/01/2014 [32.1587] RIP: 0010:__list_del_entry_valid_or_report+0x108/0x120 [32.1593] RSP: 0018:ffffaa288287fdd0 EFLAGS: 00010202 [32.1594] RAX: 0000000000000001 RBX: ffff95889326e800 RCX:ffff958890201538 [32.1596] RDX: ffff9588992bd538 RSI: ffff958890202538 RDI:ffffffff82a41e00 [32.1597] RBP: ffff958890202538 R08: ffffffff828fc1e8 R09:00000000ffffefff [32.1599] R10: ffffffff8288c200 R11: ffffffff828e4200 R12:ffff958890201538 [32.1601] R13: ffff95889326e958 R14: ffff958895c24000 R15:ffff958890202538 [32.1603] FS: 00007f0c28eb5740(0000) GS:ffff958af2bd2000(0000)knlGS:0000000000000000 [32.1605] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [32.1607] CR2: 00007f0c28e8a3cc CR3: 0000000109942005 CR4:0000000000370ef0 [32.1609] Call Trace: [32.1610] [32.1611] switch_commit_roots+0x82/0x1d0 [btrfs] [32.1615] btrfs_commit_transaction+0x968/0x1550 [btrfs] [32.1618] ? btrfs

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux
linuxlinux>= 14033b08a02916e85ffc5397e4ac15337359f3ae < 6e10283b5519d987d880d71bec90cdc7f2ec62b36e10283b5519d987d880d71bec90cdc7f2ec62b3
linuxlinux>= 14033b08a02916e85ffc5397e4ac15337359f3ae < e3d1fd084319f8f0830b22f014c7af6a96b4497be3d1fd084319f8f0830b22f014c7af6a96b4497b
linuxlinux>= 14033b08a02916e85ffc5397e4ac15337359f3ae < 4eb830847d84276f1c8ea46541cfeeedaba1fb634eb830847d84276f1c8ea46541cfeeedaba1fb63
linuxlinux>= 14033b08a02916e85ffc5397e4ac15337359f3ae < 80e1fda9c084dcf54819a12bc7682ec0afd2d8f480e1fda9c084dcf54819a12bc7682ec0afd2d8f4
linuxlinux>= 14033b08a02916e85ffc5397e4ac15337359f3ae < 201091da34c4f113af6b4a7407091c39bf29d4ca201091da34c4f113af6b4a7407091c39bf29d4ca
linuxlinux>= 14033b08a02916e85ffc5397e4ac15337359f3ae < 3a1f4264daed4b419c325a7fe35e756cada3cf823a1f4264daed4b419c325a7fe35e756cada3cf82
linuxlinux>= 6.0.19 < 6.16.1
linuxlinux_kernel
linuxlinux_kernel>= 6.0.19 < 6.1.1656.1.165
linuxlinux_kernel>= 6.13 < 6.18.146.18.14
linuxlinux_kernel>= 6.19 < 6.19.46.19.4
linuxlinux_kernel>= 6.2 < 6.6.1286.6.128
linuxlinux_kernel>= 6.7 < 6.12.756.12.75
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-aws-fips
ubuntulinux-gcp
ubuntulinux-gcp-6.8
ubuntulinux-gcp-fips
ubuntulinux-gke
ubuntulinux-gkeop
ubuntulinux-ibm

CVSS provenance

nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
vendor_redhat7.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.