{"id":"DEBIAN-CVE-2024-57806","details":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix transaction atomicity bug when enabling simple quotas  Set squota incompat bit before committing the transaction that enables the feature.  With the config CONFIG_BTRFS_ASSERT enabled, an assertion failure occurs regarding the simple quota feature.    [5.596534] assertion failed: btrfs_fs_incompat(fs_info, SIMPLE_QUOTA), in fs/btrfs/qgroup.c:365   [5.597098] ------------[ cut here ]------------   [5.597371] kernel BUG at fs/btrfs/qgroup.c:365!   [5.597946] CPU: 1 UID: 0 PID: 268 Comm: mount Not tainted 6.13.0-rc2-00031-gf92f4749861b #146   [5.598450] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/01/2014   [5.599008] RIP: 0010:btrfs_read_qgroup_config+0x74d/0x7a0   [5.604303]  \u003cTASK\u003e   [5.605230]  ? btrfs_read_qgroup_config+0x74d/0x7a0   [5.605538]  ? exc_invalid_op+0x56/0x70   [5.605775]  ? btrfs_read_qgroup_config+0x74d/0x7a0   [5.606066]  ? asm_exc_invalid_op+0x1f/0x30   [5.606441]  ? btrfs_read_qgroup_config+0x74d/0x7a0   [5.606741]  ? btrfs_read_qgroup_config+0x74d/0x7a0   [5.607038]  ? try_to_wake_up+0x317/0x760   [5.607286]  open_ctree+0xd9c/0x1710   [5.607509]  btrfs_get_tree+0x58a/0x7e0   [5.608002]  vfs_get_tree+0x2e/0x100   [5.608224]  fc_mount+0x16/0x60   [5.608420]  btrfs_get_tree+0x2f8/0x7e0   [5.608897]  vfs_get_tree+0x2e/0x100   [5.609121]  path_mount+0x4c8/0xbc0   [5.609538]  __x64_sys_mount+0x10d/0x150  The issue can be easily reproduced using the following reproducer:    root@q:linux# cat repro.sh   set -e    mkfs.btrfs -q -f /dev/sdb   mount /dev/sdb /mnt/btrfs   btrfs quota enable -s /mnt/btrfs   umount /mnt/btrfs   mount /dev/sdb /mnt/btrfs  The issue is that when enabling quotas, at btrfs_quota_enable(), we set BTRFS_QGROUP_STATUS_FLAG_SIMPLE_MODE at fs_info-\u003eqgroup_flags and persist it in the quota root in the item with the key BTRFS_QGROUP_STATUS_KEY, but we only set the incompat bit BTRFS_FEATURE_INCOMPAT_SIMPLE_QUOTA after we commit the transaction used to enable simple quotas.  This means that if after that transaction commit we unmount the filesystem without starting and committing any other transaction, or we have a power failure, the next time we mount the filesystem we will find the flag BTRFS_QGROUP_STATUS_FLAG_SIMPLE_MODE set in the item with the key BTRFS_QGROUP_STATUS_KEY but we will not find the incompat bit BTRFS_FEATURE_INCOMPAT_SIMPLE_QUOTA set in the superblock, triggering an assertion failure at:    btrfs_read_qgroup_config() -\u003e qgroup_read_enable_gen()  To fix this issue, set the BTRFS_FEATURE_INCOMPAT_SIMPLE_QUOTA flag immediately after setting the BTRFS_QGROUP_STATUS_FLAG_SIMPLE_MODE. This ensures that both flags are flushed to disk within the same transaction.","modified":"2026-09-15T09:03:00.033574291Z","published":"2025-01-11T13:15:30.597Z","upstream":["CVE-2024-57806"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-57806"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.8-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-57806.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.8-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-57806.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}