Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-74723

In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid headers [BUG] For a crafted btrfs image, the following KASAN can be triggered when...
Back to all
CVE

DEBIAN-CVE-2026-74723

In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid headers [BUG] For a crafted btrfs image, the following KASAN can be triggered when...

In the Linux kernel, the following vulnerability has been resolved:  btrfs: lzo: reject inline extents without valid headers  [BUG] For a crafted btrfs image, the following KASAN can be triggered when reading an inline lzo compressed file extent:    BUG: KASAN: slab-out-of-bounds in lzodecompress+0x57d/0x700   Read of size 4 at addr ffff888006f2e644 by task btrfslzoinlin/77    Call Trace:    <TASK>    dumpstacklvl+0x5b/0x70    printreport+0xd1/0x610    kasanreport+0xe0/0x110    asanreportloadnnoabort+0x13/0x20    lzodecompress+0x57d/0x700    btrfsdecompress+0x140/0x1c0    uncompressinline+0x147/0x1b0    btrfsgetextent+0xb23/0x10a0    btrfsdoreadpage.constprop.0+0x538/0x1ac0    btrfsreadahead+0x32f/0x5f0    readpages+0x16f/0x850    pagecacheraunbounded+0x296/0x490    dopagecachera+0xd9/0x130    pagecachesyncra+0x3ee/0x6f0    filemapgetpages+0x306/0x15c0    filemapread+0x329/0xd00    btrfsfilereaditer+0x1f8/0x2b0    vfsread+0x4ef/0x720    ksysread+0xf8/0x1d0    x64sysread+0x71/0xb0    x64syscall+0x1ab0/0x1b70    dosyscall64+0x61/0x470    entrySYSCALL64afterhwframe+0x4b/0x53    </TASK>  [CAUSE] For an inline lzo compressed file extent, there should always be one lzo header, recording the total length of the compressed data, followed by one segment header, recording the compressed lzo payload.  But if a crafted inline lzo compressed file extent contains only an lzo header, without the segment header or payload, lzodecompress() will still try to read the segment header, causing a read beyond the item boundary.  Furthermore if the inline lzo compressed file extent is the first item of the leaf, it will be at the extent buffer boundary. The above out-of-boundary read will go beyond the extent buffer boundary, triggering the above KASAN report.  [FIX] Validate the total length of the inlined lzo compressed file extent, to make sure there is at least one LZO header and one segment header, and a non-zero payload.  [ Rework the commit message to remove slop ]

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-74723

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
7.1.9-1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading