CVE-2024-23850: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation.
Affected products
- Linux Linux Kernel: up to and including 6.7.1
Published 2024-01-23. Last modified 2026-06-17.