CVE-2026-43117

Source
https://cve.org/CVERecord?id=CVE-2026-43117
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43117.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43117
Downstream
Related
Published
2026-05-06T07:40:41.862Z
Modified
2026-06-03T03:55:28.478796036Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file()
Details

In the Linux kernel, the following vulnerability has been resolved:

btrfs: tracepoints: get correct superblock from dentry in event btrfssyncfile()

If overlay is used on top of btrfs, dentry->d_sb translates to overlay's super block and fsid assignment will lead to a crash.

Use fileinode(file)->isb to always get btrfs_sb.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43117.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bc074524e123ded281cde25ebc5661910f9679e3
Fixed
4a7bab35fad5251c8cb738161152578cd83b6b9c
Fixed
520e8b4bcf872a534a7bf61ccf880047642df296
Fixed
e252db8ca2a01f82d472091f35d549b313278636
Fixed
c09a7446aab5773f38d6abb25fce99b8e1dfbc97
Fixed
32372781d664a9b03c40343e96c29d0a6139f97d
Fixed
2e4adfaec97ee053ad1bdfb5036845e66f7e0d8a
Fixed
d110d7cdb045715c0b45b0dfd974525bb38f653d
Fixed
a85b46db143fda5869e7d8df8f258ccef5fa1719

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43117.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.8.0
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.136
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.83
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.24
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.14

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43117.json"