← All Advisories

CVE-2026-97415

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97415

Key Details

CVECVE-2026-97415
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

btrfs: tree-checker: validate names in ROOT_REF and ROOT_BACKREF

ROOT_REF and ROOT_BACKREF items contain a struct btrfs_root_ref followed

by the subvolume name. Several readers assume that this layout is already

valid and then use the on-disk name length directly. A corrupted item can

therefore make those readers address bytes outside the item, and

BTRFS_IOC_GET_SUBVOL_INFO can copy too many bytes into its fixed-size UAPI

name buffer.

Validate ROOT_REF and ROOT_BACKREF items in tree-checker before any reader

uses them. Reject records that do not contain a non-empty name, whose

name_len does not exactly describe the remaining item payload, or whose

name exceeds BTRFS_NAME_LEN.

For BTRFS_IOC_GET_SUBVOL_INFO, copy only the validated on-disk name_len

instead of deriving the copy length from the item size. The ioctl result is

zeroed when allocated. That leaves the existing trailing zero byte

untouched. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97415
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97415