{"id":"DEBIAN-CVE-2026-80734","details":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: initialize inode mapping flags for cached inodes  [BUG] When running generic/795 with 8K block size, 4K page size, the test always fails, triggering some ASSERT()s related to folio size:    795 (241074): drop_caches: 3   assertion failed: IS_ALIGNED(start, blocksize) && IS_ALIGNED(end + 1, blocksize), in extent_io.c:1404 (blocksize=8192 root=262 ino=258 start=16826368 end=16830463 mapping min order=0)   ------------[ cut here ]------------   kernel BUG at extent_io.c:1404!   Oops: invalid opcode: 0000 [#1] SMP   CPU: 8 UID: 0 PID: 241105 Comm: fsstress Tainted: G           OE       7.2.0-rc5-custom+ #442 PREEMPT(full)  f4bfb352566f3949f29c233ce6f735050a03b245   Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022   RIP: 0010:assert_folio_range.cold+0x3d/0x3f [btrfs]   Call Trace:    \u003cTASK\u003e    btrfs_read_folio+0x9e/0x170 [btrfs 4cd1dd93b341b8ef766643f9512f4a86259567a3]    prepare_one_folio.constprop.0+0x104/0x2a0 [btrfs 4cd1dd93b341b8ef766643f9512f4a86259567a3]    btrfs_buffered_write+0x285/0xa50 [btrfs 4cd1dd93b341b8ef766643f9512f4a86259567a3]    btrfs_do_write_iter+0x1aa/0x210 [btrfs 4cd1dd93b341b8ef766643f9512f4a86259567a3]    iter_file_splice_write+0x31a/0x540    direct_splice_actor+0x53/0x170    splice_direct_to_actor+0xe9/0x240    do_splice_direct+0x76/0xb0    vfs_copy_file_range+0x1fd/0x630    __x64_sys_copy_file_range+0xf9/0x220    do_syscall_64+0xe1/0x790    entry_SYSCALL_64_after_hwframe+0x4b/0x53    \u003c/TASK\u003e   ---[ end trace 0000000000000000 ]---  The ASSERT() itself is added by a later patch. The crash is triggered with that new debug patch, and without this fix.  [CAUSE] In the above case, the start 16826368 is properly 8K aligned, but the end (16830463 + 1) is not 8K aligned. Furthermore the mapping's minimal folio order is 0, not the expected 1 for 8K block size with 4K page size.  So this means some inodes do not have btrfs_set_inode_mapping_order() called on it.  The missing btrfs_set_inode_mapping_order() call happens for cached inodes, through the following events:  - btrfs_create_new_inode() called for inode X   Which properly sets minimal folio order for the VFS inode.  - btrfs_update_inode() called for inode X   Which calls btrfs_delayed_update_inode() to create a delayed_node   into root-\u003edelayed_nodes xarray.  - Drop cache/memory pressure, evicting in-memory inode X   Which evicted the inode X, but delayed_node is still in   root-\u003edelayed_nodes for future reuse.  - btrfs_iget() for inode X called again    btrfs_iget()   |- btrfs_iget_locked()   |  |- iget5_locked_rcu()   |     Which creates a new vfs_inode for btrfs, whose mapping still   |     has the minimal order as 0.   |   |- btrfs_read_locked_inode()      |- btrfs_fill_inode()      |  |- btrfs_get_delayed_node()      |     Which found out the previous node, and use that delayed      |     node to initialize the new inode.      |      |- filled = true;      |- if (filled) goto cache_index;         Which skips the btrfs_update_inode_mapping_flags() and \tbtrfs_set_inode_mapping_order() calls. \tSo the inode still has minimal folio order set as 0, not \tthe required 1.  Thus later page cache read will get a folio whose size is smaller than block size, as the mapping has its minimal folio order set as 0 not 1, then trigger the ASSERT().  [FIX] Move the btrfs_update_inode_mapping_flags() and btrfs_set_inode_mapping_order() calls under cache_index label, so that the mapping flags and minimal folio order is always set no matter if we have a cached inode.","modified":"2026-09-22T08:47:27.686023230Z","published":"2026-09-03T13:06:12.200Z","upstream":["CVE-2026-80734"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-80734"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.9-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.107-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.10-1","6.16.11-1","6.16.12-1","6.16.12-1~bpo13+1","6.16.12-2","6.16.3-1","6.16.3-1~bpo13+1","6.16.5-1","6.16.6-1","6.16.7-1","6.16.8-1","6.16.9-1","6.16~rc7-1~exp1","6.17.10-1","6.17.11-1","6.17.12-1","6.17.13-1","6.17.13-1~bpo13+1","6.17.2-1~exp1","6.17.5-1~exp1","6.17.6-1","6.17.7-1","6.17.7-2","6.17.8-1","6.17.8-1~bpo13+1","6.17.9-1","6.18.1-1~exp1","6.18.10-1","6.18.12-1","6.18.12-1~bpo13+1","6.18.13-1","6.18.14-1","6.18.15-1","6.18.15-1~bpo13+1","6.18.2-1~exp1","6.18.3-1","6.18.5-1","6.18.5-1~bpo13+1","6.18.8-1","6.18.9-1","6.18.9-1~bpo13+1","6.18~rc4-1~exp1","6.18~rc4-1~exp2","6.18~rc5-1~exp1","6.18~rc6-1~exp1","6.18~rc7-1~exp1","6.19-1~exp1","6.19.10-1","6.19.10-1~bpo13+1","6.19.11-1","6.19.11-1~bpo13+1","6.19.12-1","6.19.13-1","6.19.13-1~bpo13+1","6.19.14-1","6.19.14-1~bpo13+1","6.19.2-1~exp1","6.19.3-1~exp1","6.19.4-1~exp1","6.19.5-1~exp1","6.19.6-1","6.19.6-2","6.19.6-2~bpo13+1","6.19.8-1","6.19.8-1~bpo13+1","6.19~rc4-1~exp1","6.19~rc5-1~exp1","6.19~rc6-1~exp1","6.19~rc7-1~exp1","6.19~rc8-1~exp1","7.0-1~exp1","7.0.1-1~exp1","7.0.10-1","7.0.10-1~bpo13+1","7.0.12-1","7.0.12-2","7.0.12-2~bpo13+1","7.0.13-1","7.0.13-1~bpo13+1","7.0.14-1","7.0.3-1","7.0.4-1","7.0.4-1~bpo13+1","7.0.7-1","7.0.7-1~bpo13+1","7.0.9-1","7.0.9-1~bpo13+1","7.1.1-1~exp1","7.1.2-1~exp1","7.1.3-1","7.1.3-1+sunvdc","7.1.3-1~bpo13+1","7.1.4-1","7.1.5-1","7.1.6-1","7.1.7-1","7.1.7-1~bpo13+1","7.1.8-1","7.1.8-1~bpo13+1","7.1.8-2","7.1~rc2-1~exp1","7.1~rc3-1~exp1","7.1~rc4-1~exp1","7.1~rc4-1~exp2","7.1~rc5-1~exp1","7.1~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-80734.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}