{
  "affected": [
    {
      "ranges": [
        {
          "events": [
            {
              "introduced": "0110a4c43451533de1ea1bbdc57b5d452f9d8b25"
            },
            {
              "fixed": "c372ca227e16bace86f1df1fa4ae6849e2fcfa28"
            },
            {
              "fixed": "a71143590ce9764dbcb47617647592ff8b4d48bc"
            },
            {
              "fixed": "65770111a2d47c2b15e20b2ba92bb12198f289d4"
            },
            {
              "fixed": "015dc4a1e0c2cba551d4620eba13d26d5081dc34"
            },
            {
              "fixed": "ba9fa2ff5981589bb49094d3358c339b37c47f53"
            },
            {
              "fixed": "3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1"
            },
            {
              "fixed": "9faa6b69ad73f03c7bde53e07d75a28822dc9a1a"
            },
            {
              "fixed": "486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae"
            }
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "type": "GIT"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "Linux",
        "name": "Kernel"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.20.0"
            },
            {
              "fixed": "5.10.261"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.11.0"
            },
            {
              "fixed": "5.15.212"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "5.16.0"
            },
            {
              "fixed": "6.1.178"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.2.0"
            },
            {
              "fixed": "6.6.145"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.7.0"
            },
            {
              "fixed": "6.12.97"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.13.0"
            },
            {
              "fixed": "6.18.40"
            }
          ],
          "type": "ECOSYSTEM"
        },
        {
          "events": [
            {
              "introduced": "6.19.0"
            },
            {
              "fixed": "7.1.5"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74321.json"
  },
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()\n\nIn the beginning of the loop, we try to obtain a locked delayed ref head,\nif 'locked_ref' is currently NULL, by calling btrfs_select_ref_head(),\nwhich can return an error pointer. If the error pointer is -EAGAIN we do\na continue and go back to the beginning of the loop, which will not try\nagain to call btrfs_select_ref_head() since 'locked_ref' is no longer\nNULL but it's ERR_PTR(-EAGAIN), and then we do:\n\n   spin_lock(\u0026locked_ref-\u003elock);\n\nagainst a ERR_PTR(-EAGAIN) value, generating an invalid pointer\ndereference.\n\nFix this by ensuring that 'locked_ref' is set to NULL when\nbtrfs_select_ref_head() returns ERR_PTR(-EAGAIN) and incrementing 'count'\nas well, to prevent infinite looping. We do this by doing a goto to the\nbottom of the loop that already sets 'locked_ref' to NULL and does a\ncond_resched(), with an increment to 'count' right before the goto.\nThese measures were in place before the refactoring in commit 0110a4c43451\n(\"btrfs: refactor __btrfs_run_delayed_refs loop\") but were unintentionally\nlost afterwards.",
  "id": "CVE-2026-74321",
  "modified": "2026-08-16T03:31:23.166502716Z",
  "published": "2026-08-15T05:58:17.485Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/015dc4a1e0c2cba551d4620eba13d26d5081dc34"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/3b15d02be05e74321adb1e0ae0cb4ccfba7c6cb1"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/486f8298b6188ff11ef1f4be7f1d5d2e4d1b1fae"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/65770111a2d47c2b15e20b2ba92bb12198f289d4"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/9faa6b69ad73f03c7bde53e07d75a28822dc9a1a"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/a71143590ce9764dbcb47617647592ff8b4d48bc"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/ba9fa2ff5981589bb49094d3358c339b37c47f53"
    },
    {
      "type": "WEB",
      "url": "https://git.kernel.org/stable/c/c372ca227e16bace86f1df1fa4ae6849e2fcfa28"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74321.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74321"
    },
    {
      "type": "PACKAGE",
      "url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"
    }
  ],
  "schema_version": "1.9.0",
  "summary": "btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()"
}