CVE-2026-43117
critical · 9.1In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() If overlay is used on top of btrfs, dentry->d_sb translates to overlay's super block and fsid assignment will lead to a crash. Use file_inode(file)->i_sb to always get btrfs_sb.
9.1
CVSS
0.4%
EPSS (exploit prob.)
34th
EPSS percentile
2026-05-06
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| linux | linux_kernel | >= 4.8, < 6.6.136 |
| linux | linux_kernel | >= 6.7, < 6.12.83 |
| linux | linux_kernel | >= 6.13, < 6.18.24 |
| linux | linux_kernel | >= 6.19, < 6.19.14 |
| linux | linux_kernel | 7.0 |
| linux | linux_kernel | 7.0 |
| linux | linux_kernel | 7.0 |
| linux | linux_kernel | 7.0 |
| linux | linux_kernel | 7.0 |
Check a specific version with /api/v1/cve/match.
References
- https://git.kernel.org/stable/c/2e4adfaec97ee053ad1bdfb5036845e66f7e0d8a
- https://git.kernel.org/stable/c/32372781d664a9b03c40343e96c29d0a6139f97d
- https://git.kernel.org/stable/c/4a7bab35fad5251c8cb738161152578cd83b6b9c
- https://git.kernel.org/stable/c/520e8b4bcf872a534a7bf61ccf880047642df296
- https://git.kernel.org/stable/c/a85b46db143fda5869e7d8df8f258ccef5fa1719
- https://git.kernel.org/stable/c/c09a7446aab5773f38d6abb25fce99b8e1dfbc97
- https://git.kernel.org/stable/c/d110d7cdb045715c0b45b0dfd974525bb38f653d
- https://git.kernel.org/stable/c/e252db8ca2a01f82d472091f35d549b313278636
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-43117