In the Linux kernel, the following vulnerability has been resolved:
btrfs: add the missing error handling inside getcanonicaldev_path
Inside function getcanonicaldevpath(), we call dpath() to get the final device path.
But d_path() can return error, and in that case the next strscpy() call will trigger an invalid memory access.
Add back the missing error handling for d_path().
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21679.json"
}