Out-of-bounds write in Linux kernel - CVE-2026-97415
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to perform an out-of-bounds write.
The vulnerability exists due to improper validation of root reference name lengths in Btrfs ROOT_REF and ROOT_BACKREF item handling when processing malformed Btrfs root reference items. A local user can invoke BTRFS_IOC_GET_SUBVOL_INFO on a filesystem containing a malformed ROOT_BACKREF item to perform an out-of-bounds write.