LiveActive security incident?Get immediate response
CVE Record

CVE-2023-54253: btrfs: set page extent mapped after read_folio in relocate_one_page

In the Linux kernel, the following vulnerability has been resolved: btrfs: set page extent mapped after read_folio in relocate_one_page One of the CI runs triggered the following panic assertion failed: PagePrivate(page) && page->private, in fs/btrfs/subpage.c:229 ------------[ cut here ]------------ kernel BUG at fs/btrfs/subpage.c:229! Internal error: Oops - BUG: 00000000f2000800 [#1] SMP CPU: 0 PID: 923660 Comm: btrfs Not tainted 6.5.0-rc3+ #1 pstate: 61400005 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--) pc : btrfs_subpage_assert+0xbc/0xf0 lr : btrfs_subpage_assert+0xbc/0xf0 sp : ffff800093213720 x29: ffff800093213720 x28: ffff8000932138b4 x27: 000000000c280000 x26: 00000001b5d00000 x25: 000000000c281000 x24: 000000000c281fff x23: 0000000000001000 x22: 0000000000000000 x21: ffffff42b95bf880 x20: ffff42b9528e0000 x19: 0000000000001000 x18: ffffffffffffffff x17: 667274622f736620 x16: 6e69202c65746176 x15: 0000000000000028 x14: 0000000000000003 x13: 00000000002672d7 x12: 0000000000000000 x11: ffffcd3f0ccd9204 x10: ffffcd3f0554ae50 x9 : ffffcd3f0379528c x8 : ffff800093213428 x7 : 0000000000000000 x6 : ffffcd3f091771e8 x5 : ffff42b97f333948 x4 : 0000000000000000 x3 : 0000000000000000 x2 : 0000000000000000 x1 : ffff42b9556cde80 x0 : 000000000000004f Call trace: btrfs_subpage_assert+0xbc/0xf0 btrfs_subpage_set_dirty+0x38/0xa0 btrfs_page_set_dirty+0x58/0x88 relocate_one_page+0x204/0x5f0 relocate_file_extent_cluster+0x11c/0x180 relocate_data_extent+0xd0/0xf8 relocate_block_group+0x3d0/0x4e8 btrfs_relocate_block_group+0x2d8/0x490 btrfs_relocate_chunk+0x54/0x1a8 btrfs_balance+0x7f4/0x1150 btrfs_ioctl+0x10f0/0x20b8 __arm64_sys_ioctl+0x120/0x11d8 invoke_syscall.constprop.0+0x80/0xd8 do_el0_svc+0x6c/0x158 el0_svc+0x50/0x1b0 el0t_64_sync_handler+0x120/0x130 el0t_64_sync+0x194/0x198 Code: 91098021 b0007fa0 91346000 97e9c6d2 (d4210000) This is the same problem outlined in 17b17fcd6d44 ("btrfs: set_page_extent_mapped after read_folio in btrfs_cont_expand") , and the fix is the same. I originally looked for the same pattern elsewhere in our code, but mistakenly skipped over this code because I saw the page cache readahead before we set_page_extent_mapped, not realizing that this was only in the !page case, that we can still end up with a !uptodate page and then do the btrfs_read_folio further down. The fix here is the same as the above mentioned patch, move the set_page_extent_mapped call to after the btrfs_read_folio() block to make sure that we have the subpage blocksize stuff setup properly before using the page.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This is a Linux kernel Btrfs bug that can trigger a kernel panic during Btrfs relocation or balance activity. The public bundle does not show data theft, privilege escalation, CVSS scoring, or active exploitation. Business impact is primarily availability risk for systems using affected Linux kernels with Btrfs.

Executive priority

Treat as a targeted availability risk, not a broad emergency from the current evidence. Patch through normal kernel maintenance, accelerating for production Btrfs storage systems where an unexpected panic would cause service disruption.

Technical view

In Btrfs relocate_one_page, set_page_extent_mapped was called before btrfs_read_folio completed setup for subpage blocksize state. Under the described path, this could violate PagePrivate assertions and hit a kernel BUG/Oops during relocation. The fix moves set_page_extent_mapped after the btrfs_read_folio block.

Likely exposure

Exposure is likely limited to Linux systems running affected kernel versions or commits with Btrfs in use, especially where Btrfs balance or relocation operations occur. The bundle lists Linux kernel versions including 5.12, 6.1.54, 6.5.4, and 6.6 as affected, but distribution backport status must be verified.

Exploitation context

CISA KEV is false, and the provided sources do not cite active exploitation or a public exploit. The evidence describes a CI-triggered kernel panic in a Btrfs ioctl balance path. Preconditions, attacker control, and privilege requirements are not fully established in the bundle.

Researcher notes

The source record is sparse: no CVSS, CWE, exploitability analysis, or distro-specific package matrix. The strongest evidence is the kernel fix narrative and stack trace showing a Btrfs relocation panic. Avoid extrapolating beyond Btrfs subpage/page-state handling and availability impact.

Mitigation direction

  • Update to a kernel build containing the referenced stable Btrfs fixes.
  • Check distribution advisories for backported fixes before judging version strings alone.
  • Prioritize systems using Btrfs for production or storage-heavy workloads.
  • If patching is delayed, review vendor guidance for operational workarounds.

Validation and detection

  • Inventory Linux kernel versions and identify hosts using Btrfs filesystems.
  • Confirm whether vendor kernel packages include the referenced stable commits.
  • Review logs for Btrfs balance, relocation, kernel BUG, or Oops events.
  • Test patched kernels in staging with representative Btrfs maintenance operations.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-54253 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
0ADP providers
4Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux32443de3382be98c0a8b8f6f50d23da2e10c4117, 32443de3382be98c0a8b8f6f50d23da2e10c4117, 32443de3382be98c0a8b8f6f50d23da2e10c4117unaffected
LinuxLinux5.12, 0, 6.1.54, 6.5.4, 6.6affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.