-
CVE-2026-93800
- EPSS 0.17%
- Veröffentlicht 24.09.2026 16:02:34
- Zuletzt bearbeitet 03.10.2026 11:17:49
- Erkennungen
btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()
If during relocation we fail in insert_dirty_subvol() because
btrfs_update_reloc_root() returned an error, we will leave a root's
reloc_root field pointing to a reloc root that was freed instead of NULL,
resulting later in a use-after-free, or double free attempt during
unmount.
The sequence of steps is this:
1) During relocation the call to btrfs_update_reloc_root() in
insert_dirty_subvol() fails, so insert_dirty_subvol() returns the
error to merge_reloc_root() without adding the root to the list
rc->dirty_subvol_roots;
2) Then merge_reloc_root() aborts the current transaction because
insert_dirty_subvol() returned an error;
3) Up the call chain, merge_reloc_roots() gets the error, adds the
reloc root for root X to the local reloc_roots list and jumps to the
'out' label, where it calls free_reloc_roots() to free all the reloc
roots in the local reloc_roots list. This frees the reloc root for
root X;
4) We go up the call chain to relocate_block_group() which calls
clean_dirty_subvols() to go over dirty roots and set their
->reloc_root field to NULL, but root X is not in the dirty_subvol_roots
list, so its ->reloc_root still points to a reloc root;
5) Relocation finishes, with an error and a transaction abort, but the
->reloc_root field for root X still points to the reloc root that was
freed in step 3;
6) When unmounting the fs we end up calling:
btrfs_free_fs_roots()
btrfs_drop_and_free_fs_root()
--> calls btrfs_put_root() against root X's ->reloc_root
which is not NULL and points to the already freed
reloc root in step 4 above
Resulting in a use-after-free to a double free attempt.
Syzbot reported this with the following dmesg/syslog:
[ 106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)
[ 106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure
[ 106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5
[ 106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.
[ 106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0
[ 106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure
[ 106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly
[ 106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure
[ 106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1
[ 106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30
[ 106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30
[ 106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409
[ 106.682946][ T5338] ==================================================================
[ 106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250
[ 106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338
[ 106.693173][ T5338]
[ 106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
[ 106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 106.694300][ T5338] Call Trace:
[ 106.694308][ T5338] <TASK>
[ 106.694314][ T5338] dump_stack_lvl+0xe8/0x150
[ 106.694331][ T5338] print_address_description+0x55/0x1e0
[ 106.694343][ T5338] ? btrfs_put_root+0x2f/0x250
[ 106.694358][ T5338] print_report+0x58/0x70
[ 106.
---truncated---Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
f32b84d7c977e1906a4781b93b3c93090b6cd675
Version <
5a247097c5f94b51ffc991b444d998ad6e85875f
Status
affected
Version
592fbcd50c99b8adf999a2a54f9245caff333139
Version <
6372dd394ea907cd85a7a8063db320ec73dfaed0
Status
affected
Version
592fbcd50c99b8adf999a2a54f9245caff333139
Version <
9f599d120b2b79d2d937c3935b7cdf2697514283
Status
affected
Version
592fbcd50c99b8adf999a2a54f9245caff333139
Version <
a01837ae174a2a968c245a30e6dd010f50eaf05d
Status
affected
Version
592fbcd50c99b8adf999a2a54f9245caff333139
Version <
97a540d72ebcb21853d11f2a56782fe377f358e7
Status
affected
Version
592fbcd50c99b8adf999a2a54f9245caff333139
Version <
fda1b6636ff1846f00643e791099db5564b547d9
Status
affected
Version
592fbcd50c99b8adf999a2a54f9245caff333139
Version <
83201804efa4a5168be754e1dfc9b2faee760cac
Status
affected
Version
aa18bc1ff8a51f082d5b3b6d07693797637b4028
Status
affected
Version
4cb0aea2e250eee35ccfac5f5395cd8f3238a9e5
Status
affected
Version
5.10.36
Version <
5.10.271
Status
affected
Version
5.11.20
Version <
5.12
Status
affected
Version
5.12.3
Version <
5.13
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.13
Status
affected
Version
0
Version <
5.13
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.111
Status
unaffected
Version <=
6.18.*
Version
6.18.53
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.052 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/97a540d72ebcb21853d11f2a56782fe377f358e7
https://git.kernel.org/stable/c/fda1b6636ff1846f00643e791099db5564b547d9
https://git.kernel.org/stable/c/83201804efa4a5168be754e1dfc9b2faee760cac
https://git.kernel.org/stable/c/5a247097c5f94b51ffc991b444d998ad6e85875f
https://git.kernel.org/stable/c/6372dd394ea907cd85a7a8063db320ec73dfaed0
https://git.kernel.org/stable/c/9f599d120b2b79d2d937c3935b7cdf2697514283
https://git.kernel.org/stable/c/a01837ae174a2a968c245a30e6dd010f50eaf05d