CVE-2021-47145: btrfs: do not BUG_ON in link_to_fixup_dir
In the Linux kernel, the following vulnerability has been resolved:
btrfs: do not BUG_ON in link_to_fixup_dir
While doing error injection testing I got the following panic
kernel BUG at fs/btrfs/tree-log.c:1862!
invalid opcode: 0000 [#1] SMP NOPTI
CPU: 1 PID: 7836 Comm: mount Not tainted 5.13.0-rc1+ #305
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.13.0-2.fc32 04/01/2014
RIP: 0010:link_to_fixup_dir+0xd5/0xe0
RSP: 0018:ffffb5800180fa30 EFLAGS: 00010216
RAX: fffffffffffffffb RBX: 00000000fffffffb RCX: ffff8f595287faf0
RDX: ffffb5800180fa37 RSI: ffff8f5954978800 RDI: 0000000000000000
RBP: ffff8f5953af9450 R08: 0000000000000019 R09: 0000000000000001
R10: 000151f408682970 R11: 0000000120021001 R12: ffff8f5954978800
R13: ffff8f595287faf0 R14: ffff8f5953c77dd0 R15: 0000000000000065
FS: 00007fc5284c8c40(0000) GS:ffff8f59bbd00000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fc5287f47c0 CR3: 000000011275e002 CR4: 0000000000370ee0
Call Trace:
replay_one_buffer+0x409/0x470
? btree_read_extent_buffer_pages+0xd0/0x110
walk_up_log_tree+0x157/0x1e0
walk_log_tree+0xa6/0x1d0
btrfs_recover_log_trees+0x1da/0x360
? replay_one_extent+0x7b0/0x7b0
open_ctree+0x1486/0x1720
btrfs_mount_root.cold+0x12/0xea
? __kmalloc_track_caller+0x12f/0x240
legacy_get_tree+0x24/0x40
vfs_get_tree+0x22/0xb0
vfs_kern_mount.part.0+0x71/0xb0
btrfs_mount+0x10d/0x380
? vfs_parse_fs_string+0x4d/0x90
legacy_get_tree+0x24/0x40
vfs_get_tree+0x22/0xb0
path_mount+0x433/0xa10
__x64_sys_mount+0xe3/0x120
do_syscall_64+0x3d/0x80
entry_SYSCALL_64_after_hwframe+0x44/0xae
We can get -EIO or any number of legitimate errors from
btrfs_search_slot(), panicing here is not the appropriate response. The
error path for this code handles errors properly, simply return the
error.
Security readout for executives and security teams
Plain-English summary
This Linux kernel Btrfs bug can turn recoverable filesystem errors into a kernel panic during mount-time log recovery. For businesses, the main concern is availability: affected Btrfs systems may crash instead of handling an error cleanly. The supplied sources do not show active exploitation or a CVSS score.
Executive priority
Treat as a normal-priority availability fix unless critical Btrfs-backed systems are exposed. Escalate patching for infrastructure where an unexpected kernel panic would cause material outage or recovery delays.
Technical view
In Btrfs tree-log recovery, link_to_fixup_dir used BUG_ON after btrfs_search_slot returned legitimate errors such as EIO. The fix changes the behavior to return the error through the existing error path instead of panicking. Evidence points to a kernel availability defect, not disclosed privilege escalation or remote execution.
Likely exposure
Exposure is likely limited to Linux systems using Btrfs on affected kernel versions or vendor builds missing the referenced stable fixes. Systems not using Btrfs are unlikely to be exposed based on the supplied evidence.
Exploitation context
The source describes error-injection testing causing a panic during mount. The supplied bundle marks KEV as false and provides no cited evidence of active exploitation, public weaponization, or remote triggering.
Researcher notes
The record lacks CVSS, CWE, and exploit evidence. Analysis should stay centered on Btrfs error handling during log replay. The commit references are the strongest remediation evidence; distribution package mapping still requires vendor-specific confirmation.
Mitigation direction
Update affected Linux kernels through the relevant distribution or vendor channel.
Prioritize hosts that use Btrfs for root, data, or mounted volumes.
Confirm the installed kernel includes the referenced stable Btrfs fix.
Follow vendor advisories for exact fixed package versions.
Plan reboot windows where kernel updates require restart.
Validation and detection
Inventory systems using Btrfs filesystems.
Compare running kernel builds against vendor fixed versions or stable commits.
Review kernel changelogs for "btrfs: do not BUG_ON in link_to_fixup_dir".
Check crash logs for Btrfs mount or log-recovery panics.
Validate patched kernels in staging before production rollout.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2021-47145 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.