Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-37827 – Here is a title for the vulnerability:“btrfs: RAID1 Profile Write Pointer Offset Mismatch NULL Pointer Dereference”

    CVE-2025-37827 – Here is a title for the vulnerability:“btrfs: RAID1 Profile Write Pointer Offset Mismatch NULL Pointer Dereference”

    May 8, 2025

    CVE ID : CVE-2025-37827

    Published : May 8, 2025, 7:15 a.m. | 58 minutes ago

    Description : In the Linux kernel, the following vulnerability has been resolved:

    btrfs: zoned: return EIO on RAID1 block group write pointer mismatch

    There was a bug report about a NULL pointer dereference in
    __btrfs_add_free_space_zoned() that ultimately happens because a
    conversion from the default metadata profile DUP to a RAID1 profile on two
    disks.

    The stack trace has the following signature:

    BTRFS error (device sdc): zoned: write pointer offset mismatch of zones in raid1 profile
    BUG: kernel NULL pointer dereference, address: 0000000000000058
    #PF: supervisor read access in kernel mode
    #PF: error_code(0x0000) – not-present page
    PGD 0 P4D 0
    Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI
    RIP: 0010:__btrfs_add_free_space_zoned.isra.0+0x61/0x1a0
    RSP: 0018:ffffa236b6f3f6d0 EFLAGS: 00010246
    RAX: 0000000000000000 RBX: ffff96c8132f3400 RCX: 0000000000000001
    RDX: 0000000010000000 RSI: 0000000000000000 RDI: ffff96c8132f3410
    RBP: 0000000010000000 R08: 0000000000000003 R09: 0000000000000000
    R10: 0000000000000000 R11: 00000000ffffffff R12: 0000000000000000
    R13: ffff96c758f65a40 R14: 0000000000000001 R15: 000011aac0000000
    FS: 00007fdab1cb2900(0000) GS:ffff96e60ca00000(0000) knlGS:0000000000000000
    CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
    CR2: 0000000000000058 CR3: 00000001a05ae000 CR4: 0000000000350ef0
    Call Trace:

    ? __die_body.cold+0x19/0x27
    ? page_fault_oops+0x15c/0x2f0
    ? exc_page_fault+0x7e/0x180
    ? asm_exc_page_fault+0x26/0x30
    ? __btrfs_add_free_space_zoned.isra.0+0x61/0x1a0
    btrfs_add_free_space_async_trimmed+0x34/0x40
    btrfs_add_new_free_space+0x107/0x120
    btrfs_make_block_group+0x104/0x2b0
    btrfs_create_chunk+0x977/0xf20
    btrfs_chunk_alloc+0x174/0x510
    ? srso_return_thunk+0x5/0x5f
    btrfs_inc_block_group_ro+0x1b1/0x230
    btrfs_relocate_block_group+0x9e/0x410
    btrfs_relocate_chunk+0x3f/0x130
    btrfs_balance+0x8ac/0x12b0
    ? srso_return_thunk+0x5/0x5f
    ? srso_return_thunk+0x5/0x5f
    ? __kmalloc_cache_noprof+0x14c/0x3e0
    btrfs_ioctl+0x2686/0x2a80
    ? srso_return_thunk+0x5/0x5f
    ? ioctl_has_perm.constprop.0.isra.0+0xd2/0x120
    __x64_sys_ioctl+0x97/0xc0
    do_syscall_64+0x82/0x160
    ? srso_return_thunk+0x5/0x5f
    ? __memcg_slab_free_hook+0x11a/0x170
    ? srso_return_thunk+0x5/0x5f
    ? kmem_cache_free+0x3f0/0x450
    ? srso_return_thunk+0x5/0x5f
    ? srso_return_thunk+0x5/0x5f
    ? syscall_exit_to_user_mode+0x10/0x210
    ? srso_return_thunk+0x5/0x5f
    ? do_syscall_64+0x8e/0x160
    ? sysfs_emit+0xaf/0xc0
    ? srso_return_thunk+0x5/0x5f
    ? srso_return_thunk+0x5/0x5f
    ? seq_read_iter+0x207/0x460
    ? srso_return_thunk+0x5/0x5f
    ? vfs_read+0x29c/0x370
    ? srso_return_thunk+0x5/0x5f
    ? srso_return_thunk+0x5/0x5f
    ? syscall_exit_to_user_mode+0x10/0x210
    ? srso_return_thunk+0x5/0x5f
    ? do_syscall_64+0x8e/0x160
    ? srso_return_thunk+0x5/0x5f
    ? exc_page_fault+0x7e/0x180
    entry_SYSCALL_64_after_hwframe+0x76/0x7e
    RIP: 0033:0x7fdab1e0ca6d
    RSP: 002b:00007ffeb2b60c80 EFLAGS: 00000246 ORIG_RAX: 0000000000000010
    RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007fdab1e0ca6d
    RDX: 00007ffeb2b60d80 RSI: 00000000c4009420 RDI: 0000000000000003
    RBP: 00007ffeb2b60cd0 R08: 0000000000000000 R09: 0000000000000013
    R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
    R13: 00007ffeb2b6343b R14: 00007ffeb2b60d80 R15: 0000000000000001

    CR2: 0000000000000058
    —[ end trace 0000000000000000 ]—

    The 1st line is the most interesting here:

    BTRFS error (device sdc): zoned: write pointer offset mismatch of zones in raid1 profile

    When a RAID1 block-group is created and a write pointer mismatch between
    the disks in the RAID set is detected, btrfs sets the alloc_offset to the
    length of the block group marking it as full. Afterwards the code expects
    that a balance operation will evacuate the data in this block-group and
    repair the problems.

    But before this is possible, the new space of this block-group will be
    accounted in the free space cache. But in __btrfs_
    —truncated—

    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-37819 – “Linux Kernel GICv2m Use After Free Vulnerability in irqchip”
    Next Article CVE-2025-37821 – Linux Kernel Sched Eevdf Crash

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 17, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-4610 – WordPress WP-Members Membership Plugin Stored Cross-Site Scripting Vulnerability

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    NativePHP for Mobile v1 — Launching May 2

    Development

    Digital meets Physical: Risograph Printing with WebGL

    Development

    CVE-2025-29746 – Koillection Cross Site Scripting (XSS)

    Common Vulnerabilities and Exposures (CVEs)

    SVAR Svelte Editor: Easy Way to Edit Structured Data Records

    Development

    Highlights

    News & Updates

    Obsidian is trolling all of us by disabling one of Avowed’s most useful settings by default, and we’re mad about it

    February 20, 2025

    Why they decided to disable the ability to see such important objects on the compass…

    Should you buy a cheap robot vacuum? This $400 model proves it might even be a great idea

    January 24, 2025

    What is CSS Nesting Explained

    February 11, 2025

    CVE-2024-57394 – Qi-ANXIN Tianqing Endpoint Security Management System DLL Hijacking Vulnerability

    April 21, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.