← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 22, 2026 · 16:16via CVEFeed

CVE-2026-74723 - btrfs: lzo: reject inline extents without valid headers

Brief

CVE ID : CVE-2026-74723

Published : Aug. 22, 2026, 4:16 p. m.

  • 4 hours, 54 minutes ago

Description : In the Linux kernel, the following vulnerability has been resolved:

btrfs: lzo: reject inline extents without valid headers

[BUG] For a crafted btrfs image, the following KASAN can be triggered when reading an inline lzo compressed file extent:

BUG: KASAN: slab-out-of-bounds in lzo_decompress+0x57d/0x700 Read of size 4 at addr ffff888006f2e644 by task btrfs_lzo_inlin/77

Call Trace:

Read more on CVEFeed