
Cloud Vulnerability DB
A community-led vulnerabilities database
In the Linux kernel, a vulnerability was identified and resolved in the BTRFS filesystem component, specifically related to the btrfsshowdevname function. The issue was discovered when the test case btrfs/238 reported warnings during device name display operations in the filesystem (Kernel Commit).
The vulnerability occurs when btrfspreparesprout() moves the fsdevices::devices into fsdevices::seedlist, causing btrfsshow_devname() to search for devices and find none, which leads to warning messages. The issue specifically affects the device name display functionality in /proc/self/mounts (Kernel Commit).
The vulnerability could potentially cause system warnings and incorrect device name display in the BTRFS filesystem, affecting system monitoring and filesystem operations (Kernel Commit).
The issue has been fixed by updating the code to use latest_dev pointer, which is always valid as it's assigned before device deletion from the list in remove or replace operations. The RCU protection ensures the device structure remains valid until after synchronization (Kernel Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."