A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag().
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 5.11 | 5.15.63 |
| linux / linux_kernel | 5.16 | 5.19.4 |
| linux / linux_kernel | 5.5 | 5.10.184 |
| linux / linux_kernel | 4.20 | 5.4.247 |
| linux / linux_kernel | 4.15 | 4.19.286 |
| linux / linux_kernel | 2.6.31 | 4.14.318 |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |