Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2025-40100 — kernel

⚪ Unknown ✅ No Known Exploit NVD
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

btrfs: do not assert we found block group item when creating free space tree

In the Linux kernel, the following vulnerability has been resolved:

btrfs: do not assert we found block group item when creating free space tree

Currently, when building a free space tree at populate_free_space_tree(),

if we are not using the block group tree feature, we always expect to find

block group items (either extent items or a block group item with key type

BTRFS_BLOCK_GROUP_ITEM_KEY) when we search the extent tree with

btrfs_search_slot_for_read(), so we assert that we found an item. However

this expectation is wrong since we can have a new block group created in

the current transaction which is still empty and for which we still have

not added the block group's item to the extent tree, in which case we do

not have any items in the extent tree associated to the block group.

The insertion of a new block group's block group item in the extent tree

happens at btrfs_create_pending_block_groups() when it calls the helper

insert_block_group_item(). This typically is done when a transaction

handle is released, committed or when running delayed refs (either as

part of a transaction commit or when serving tickets for space reservation

if we are low on free space).

So remove the assertion at populate_free_space_tree() even when the block

group tree feature is not enabled and update the comment to mention this

case.

Syzbot reported this with the following stack trace:

BTRFS info (device loop3 state M): rebuilding free space tree

assertion failed: ret == 0 :: 0, in fs/btrfs/free-space-tree.c:1115

------------[ cut here ]------------

kernel BUG at fs/btrfs/free-space-tree.c:1115!

Oops: invalid opcode: 0000 [#1] SMP KASAN PTI

CPU: 1 UID: 0 PID: 6352 Comm: syz.3.25 Not tainted syzkaller #0 PREEMPT(full)

Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025

RIP: 0010:populate_free_space_tree+0x700/0x710 fs/btrfs/free-space-tree.c:1115

Code: ff ff e8 d3 (...)

RSP: 0018:ffffc9000430f780 EFLAGS: 00010246

RAX: 0000000000000043 RBX: ffff88805b709630 RCX: fea61d0e2e79d000

RDX: 0000000000000000 RSI: 0000000080000000 RDI: 0000000000000000

RBP: ffffc9000430f8b0 R08: ffffc9000430f4a7 R09: 1ffff92000861e94

R10: dffffc0000000000 R11: fffff52000861e95 R12: 0000000000000001

R13: 1ffff92000861f00 R14: dffffc0000000000 R15: 0000000000000000

FS: 00007f424d9fe6c0(0000) GS:ffff888125afc000(0000) knlGS:0000000000000000

CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033

CR2: 00007fd78ad212c0 CR3: 0000000076d68000 CR4: 00000000003526f0

Call Trace:

<TASK>

btrfs_rebuild_free_space_tree+0x1ba/0x6d0 fs/btrfs/free-space-tree.c:1364

btrfs_start_pre_rw_mount+0x128f/0x1bf0 fs/btrfs/disk-io.c:3062

btrfs_remount_rw fs/btrfs/super.c:1334 [inline]

btrfs_reconfigure+0xaed/0x2160 fs/btrfs/super.c:1559

reconfigure_super+0x227/0x890 fs/super.c:1076

do_remount fs/namespace.c:3279 [inline]

path_mount+0xd1a/0xfe0 fs/namespace.c:4027

do_mount fs/namespace.c:4048 [inline]

__do_sys_mount fs/namespace.c:4236 [inline]

__se_sys_mount+0x313/0x410 fs/namespace.c:4213

do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]

do_syscall_64+0xfa/0xfa0 arch/x86/entry/syscall_64.c:94

entry_SYSCALL_64_after_hwframe+0x77/0x7f

RIP: 0033:0x7f424e39066a

Code: d8 64 89 02 (...)

RSP: 002b:00007f424d9fde68 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5

RAX: ffffffffffffffda RBX: 00007f424d9fdef0 RCX: 00007f424e39066a

RDX: 0000200000000180 RSI: 0000200000000380 RDI: 0000000000000000

RBP: 0000200000000180 R08: 00007f424d9fdef0 R09: 0000000000000020

R10: 0000000000000020 R11: 0000000000000246 R12: 0000200000000380

R13: 00007f424d9fdeb0 R14: 0000000000000000 R15: 00002000000002c0

</TASK>

Modules linked in:

---[ end trace 0000000000000000 ]---

Affected software

CVE-2025-40100 is recorded against 2 packages.

  • kernel (from 6.13.0 up to 6.17.5)
  • unknown

Timeline and source

Published on 30 October 2025 and last revised on 12 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2025-40100 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-10-30
Updated 2026-08-20
Modified 2026-08-12
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 6.13.0 6.17.5
unknown

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2025-40100?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2025-40100 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.