SB2026040663 - Always-Incorrect Control Flow Implementation in Linux kernel btrfs



SB2026040663 - Always-Incorrect Control Flow Implementation in Linux kernel btrfs

Published: April 6, 2026

Security Bulletin ID SB2026040663
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-23465)

The vulnerability allows a local user to cause data loss.

The vulnerability exists due to improper handling of directory entry logging in btrfs directory logging when logging the parent directory of a conflicting inode during fsync and log replay conditions. A local user can create and remove directories and files and trigger fsync operations to cause data loss.

After a power failure and log replay, newly created directory entries may be missing because the parent directory can be marked as logged without its new dentries being recorded.


Remediation

Install update from vendor's website.