{"apiVersion":"1.0","identifier":"CVE-2026-74571","description":"In the Linux kernel, the following vulnerability has been resolved: btrfs: skip global block reserve accounting for rescue mounts [BUG] Mounting with rescue=ibadroots after corrupting the block group tree root triggers a NULL pointer dereference: BUG: kernel NULL pointer dereference, address: 0000000000000100 RIP: 0010:btrfs_update_global_block_rsv+0x9d/0x1c0 [btrfs] Call Trace: fill_dummy_bgs+0xd4/0x120 [btrfs] open_ctree+0xc6e/0x1ca0 [btrfs] btrfs_get_tree+0x50d/0xa40 [btrfs] The same crash occurs with a corrupted raid stripe tree root, via btrfs_read_block_groups() instead of fill_dummy_bgs(). [CAUSE] With rescue=ibadroots, btrfs_read_roots() allows the mount to continue when either root cannot be read, leaving the corresponding root pointer NULL while its on-disk feature bit remains set. btrfs_update_global_block_rsv() then dereferences the missing root based on the feature bit alone. [FIX] Rescue mounts are fully read-only and cannot start transactions, so the global reserve is never consumed. Under btrfs_is_full_ro(), mark the reserve as full and return before performing the accounting. And since we need to check if the fs is mount fully RO, export fs_is_full_ro() as btrfs_is_full_ro(), and move it to fs.h. [ Squash the fs_is_full_ro() export commit into this one. ]","publishedAt":"2026-08-15T13:18:02","lastModifiedAt":"2026-08-17T06:19:55","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74571","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00145,"riskScore":0,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74571","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74571","en":"https://www.redsauce.net/en/cves/CVE-2026-74571","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74571","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74571","de":"https://www.redsauce.net/de/cves/CVE-2026-74571","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74571","el":"https://www.redsauce.net/el/cves/CVE-2026-74571"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74571"}}