CVE-2026-23141: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: btrfs: send: check for inline extents in range_is_hole_in_parent() Before accessing the disk_bytenr field of a file extent item we need to check if we are dealing with an inline extent. This is because for inline extents their data starts at the offset of the disk_bytenr field. So accessing the disk_bytenr means we are accessing inline data or in case the inline data is less than 8 bytes we can actually cause an invalid memory access if this inline extent item is the first item in the leaf or access metadata from other items.
Affected products
- Linux Linux Kernel: from 4.11, before 6.6.122 (fixed in 6.6.122); from 6.7, before 6.12.67 (fixed in 6.12.67); from 6.13, before 6.18.7 (fixed in 6.18.7); version 6.19 only
Published 2026-02-14. Last modified 2026-06-17.