CVE-2025-21679 Information

Description

In the Linux kernel the following vulnerability has been resolved:

btrfs: add the missing error handling inside get_canonical_dev_path

Inside function get_canonical_dev_path() we call d_path() to get the final device path.

But d_path() can return error and in that case the next strscpy() call will trigger an invalid memory access.

Add back the missing error handling for d_path().

Reference

https://git.kernel.org/stable/c/d0fb5741932b831eded49bfaaf33353e96200d6d https://git.kernel.org/stable/c/fe4de594f7a2e9bc49407de60fbd20809fad4192

Share on: