-

CVE-2026-93800

btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()

In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()

If during relocation we fail in insert_dirty_subvol() because
btrfs_update_reloc_root() returned an error, we will leave a root's
reloc_root field pointing to a reloc root that was freed instead of NULL,
resulting later in a use-after-free, or double free attempt during
unmount.

The sequence of steps is this:

1) During relocation the call to btrfs_update_reloc_root() in
   insert_dirty_subvol() fails, so insert_dirty_subvol() returns the
   error to merge_reloc_root() without adding the root to the list
   rc->dirty_subvol_roots;

2) Then merge_reloc_root() aborts the current transaction because
   insert_dirty_subvol() returned an error;

3) Up the call chain, merge_reloc_roots() gets the error, adds the
   reloc root for root X to the local reloc_roots list and jumps to the
   'out' label, where it calls free_reloc_roots() to free all the reloc
   roots in the local reloc_roots list. This frees the reloc root for
   root X;

4) We go up the call chain to relocate_block_group() which calls
   clean_dirty_subvols() to go over dirty roots and set their
   ->reloc_root field to NULL, but root X is not in the dirty_subvol_roots
   list, so its ->reloc_root still points to a reloc root;

5) Relocation finishes, with an error and a transaction abort, but the
   ->reloc_root field for root X still points to the reloc root that was
   freed in step 3;

6) When unmounting the fs we end up calling:

     btrfs_free_fs_roots()
        btrfs_drop_and_free_fs_root()
           --> calls btrfs_put_root() against root X's ->reloc_root
               which is not NULL and points to the already freed
               reloc root in step 4 above

  Resulting in a use-after-free to a double free attempt.

Syzbot reported this with the following dmesg/syslog:

   [  106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)
   [  106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure
   [  106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5
   [  106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.
   [  106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0
   [  106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure
   [  106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly
   [  106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure
   [  106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1
   [  106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30
   [  106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30
   [  106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409
   [  106.682946][ T5338] ==================================================================
   [  106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250
   [  106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338
   [  106.693173][ T5338]
   [  106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
   [  106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
   [  106.694300][ T5338] Call Trace:
   [  106.694308][ T5338]  <TASK>
   [  106.694314][ T5338]  dump_stack_lvl+0xe8/0x150
   [  106.694331][ T5338]  print_address_description+0x55/0x1e0
   [  106.694343][ T5338]  ? btrfs_put_root+0x2f/0x250
   [  106.694358][ T5338]  print_report+0x58/0x70
   [  106.
---truncated---
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f32b84d7c977e1906a4781b93b3c93090b6cd675
Version < 5a247097c5f94b51ffc991b444d998ad6e85875f
Status affected
Version 592fbcd50c99b8adf999a2a54f9245caff333139
Version < 6372dd394ea907cd85a7a8063db320ec73dfaed0
Status affected
Version 592fbcd50c99b8adf999a2a54f9245caff333139
Version < 9f599d120b2b79d2d937c3935b7cdf2697514283
Status affected
Version 592fbcd50c99b8adf999a2a54f9245caff333139
Version < a01837ae174a2a968c245a30e6dd010f50eaf05d
Status affected
Version 592fbcd50c99b8adf999a2a54f9245caff333139
Version < 97a540d72ebcb21853d11f2a56782fe377f358e7
Status affected
Version 592fbcd50c99b8adf999a2a54f9245caff333139
Version < fda1b6636ff1846f00643e791099db5564b547d9
Status affected
Version 592fbcd50c99b8adf999a2a54f9245caff333139
Version < 83201804efa4a5168be754e1dfc9b2faee760cac
Status affected
Version aa18bc1ff8a51f082d5b3b6d07693797637b4028
Status affected
Version 4cb0aea2e250eee35ccfac5f5395cd8f3238a9e5
Status affected
Version 5.10.36
Version < 5.10.271
Status affected
Version 5.11.20
Version < 5.12
Status affected
Version 5.12.3
Version < 5.13
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.13
Status affected
Version 0
Version < 5.13
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.052
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/97a540d72ebcb21853d11f2a56782fe377f358e7
https://git.kernel.org/stable/c/fda1b6636ff1846f00643e791099db5564b547d9
https://git.kernel.org/stable/c/83201804efa4a5168be754e1dfc9b2faee760cac
https://git.kernel.org/stable/c/5a247097c5f94b51ffc991b444d998ad6e85875f
https://git.kernel.org/stable/c/6372dd394ea907cd85a7a8063db320ec73dfaed0
https://git.kernel.org/stable/c/9f599d120b2b79d2d937c3935b7cdf2697514283
https://git.kernel.org/stable/c/a01837ae174a2a968c245a30e6dd010f50eaf05d