CVE-2026-23141: btrfs: send: check for inline extents in range_is_hole_in_parent()

Published Feb 14, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

btrfs: send: check for inline extents in rangeisholeinparent()

Before accessing the diskbytenr field of a file extent item we need to check if we are dealing with an inline extent. This is because for inline extents their data starts at the offset of the diskbytenr field. So accessing the diskbytenr means we are accessing inline data or in case the inline data is less than 8 bytes we can actually cause an invalid memory access if this inline extent item is the first item in the leaf or access metadata from other items.

Affected Software

9 affected components
linux/kernel
Linux Linux kernel>=4.11<6.6.122
Linux Linux kernel>=6.7<6.12.67
Linux Linux kernel>=6.13<6.18.7
Linux Linux kernel=6.19-rc1
Linux Linux kernel=6.19-rc2
Linux Linux kernel=6.19-rc3
Linux Linux kernel=6.19-rc4
Linux Linux kernel=6.19-rc5

Event History

Feb 14, 2026
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-23141?

CVE-2026-23141 has a medium severity rating of 5.5 according to the CVSS 3.1 metrics.

2

What does CVE-2026-23141 affect?

CVE-2026-23141 affects the btrfs file system in the Linux kernel.

3

How do I fix CVE-2026-23141?

To fix CVE-2026-23141, apply the patch available for the Linux kernel.

4

What could happen if CVE-2026-23141 is exploited?

If exploited, CVE-2026-23141 could lead to data loss or system instability due to improper handling of inline extents.

5

When was CVE-2026-23141 published?

CVE-2026-23141 was published on February 14, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203