5.5

CVE-2026-98080

btrfs: do not force reloc root creation during qgroup_account_snapshot()

In the Linux kernel, the following vulnerability has been resolved:

btrfs: do not force reloc root creation during qgroup_account_snapshot()

[BUG]
When running btrfs/252 with quota enabled through MKFS_OPTIONS="-O quota",
it has a high chance to trigger the following kernel warning and flips
the fs RO:

  BTRFS info (device dm-2): relocating block group 30408704 flags metadata|dup
  ------------[ cut here ]------------
  WARNING: fs/btrfs/extent-tree.c:879 at lookup_inline_extent_backref+0x74b/0x960 [btrfs], CPU#4: btrfs/2173
  CPU: 4 UID: 0 PID: 2173 Comm: btrfs Not tainted 7.2.0-rc6-custom+ #457 PREEMPT(full)  3adc6528fb66f7a55fe1095385818e742f200aab
  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022
  RIP: 0010:lookup_inline_extent_backref+0x74b/0x960 [btrfs]
  Call Trace:
   <TASK>
   insert_inline_extent_backref+0x7c/0x160 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   __btrfs_inc_extent_ref+0xa9/0x270 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   __btrfs_run_delayed_refs+0x4af/0x11c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_run_delayed_refs+0x9d/0xf0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   create_pending_snapshot+0x39d/0xf00 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   create_pending_snapshots+0x9b/0xc0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_commit_transaction+0x280/0xeb0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   prepare_to_relocate+0x147/0x200 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   relocate_block_group+0x6b/0x5e0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_relocate_block_group+0x92c/0x2380 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_relocate_chunk+0x3f/0x1a0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_balance+0xa2c/0x19c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_ioctl+0x2839/0x2d30 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   __x64_sys_ioctl+0x416/0x9a0
   do_syscall_64+0xe1/0x790
   entry_SYSCALL_64_after_hwframe+0x4b/0x53
   </TASK>
  ---[ end trace 0000000000000000 ]---
  BTRFS info (device dm-2): leaf 4593991680 gen 233 total ptrs 175 free space 5953 owner 2
  BTRFS info (device dm-2): refs 3 lock_owner 2173 current 2173
  	item 0 key (166772736 METADATA_ITEM 1) itemoff 16250 itemsize 33
  		extent refs 1 gen 222 flags 2
  		ref#0: tree block backref root 266
         [ Skip the tree dump ]
  	item 174 key (263225344 METADATA_ITEM 0) itemoff 10328 itemsize 33
  		extent refs 1 gen 162 flags 258
  		ref#0: tree block backref root 267
  BTRFS error (device dm-2): extent item not found for insert, bytenr 179847168 num_bytes 16384 parent 4594335744 root_objectid 273 owner 0 offset 0
  BTRFS error (device dm-2): failed to run delayed ref for logical 179847168 num_bytes 16384 type 182 action 1 ref_mod 1: -117

[CAUSE]
The above error is showing that there is a tree reference to a metadata
extent that is no longer there.

With "ref_verify" mount option (requires CONFIG_BTRFS_DEBUG), there is
some extra debug output:

  BTRFS error (device dm-2): dumping block entry [180961280 16384], num_refs 0, metadata 1, from disk 0
  BTRFS error (device dm-2):   root entry 256, num_refs 18446744073709551615
  BTRFS error (device dm-2):   root entry 273, num_refs 18446744073709551615
  BTRFS error (device dm-2):   Ref action 3, root 273, ref_root 273, parent 0, owner 0, offset 0, num_refs 1
     btrfs_force_cow_block+0x129/0x7d0 [btrfs]
     btrfs_cow_block+0x10a/0x250 [btrfs]
     btrfs_search_slot+0x5eb/0xf40 [btrfs]
     btrfs_insert_empty_items+0x3a/0x70 [btrfs]
     insert_with_overflow+0x53/0x130 [btrfs]
     btrfs_insert_dir_item+0x125/0x290 [btrfs]
     btrfs_add_link+0xaa/0x410 [btrfs]
     btrfs_rename+0x5ea/0xcd0 [btrfs]
     btrfs_rename2+0x28/0x60 [btrfs]
     vfs_rename+0x5b2/0xe10
     filename_renameat2+0x244/0x430
     __x64_sys_rename+0x48/0x70
     do_syscall_64+0xe1/0x790
     entry_SYSCALL_64_after_hwframe+0x4b/0x53
 
---truncated---
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 4.14.45 < 4.15
Linux ≫ Linux Kernel Version >= 4.16.13 < 5.10.271
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.222
Linux ≫ Linux Kernel Version >= 6.0 < 6.1.189
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.158
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.111
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.53
Linux ≫ Linux Kernel Version >= 6.19 < 7.2.7
Linux ≫ Linux Kernel Version 7.3 Update rc1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-672 Operation on a Resource after Expiration or Release

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

https://git.kernel.org/stable/c/c4c78768d1a8ceb713693cc5524acbe984c31f3c
Patch
https://git.kernel.org/stable/c/203cbfb4fba590bd9b08bd36fa6d05b5d28923bf
Patch
https://git.kernel.org/stable/c/b5d5ab5a715001dd937c920ef8c5688fd4999ba1
Patch
https://git.kernel.org/stable/c/cacf35832292997018837e484283f95a9301ebf5
Patch
https://git.kernel.org/stable/c/21bd77c132f18dc21c6fcdf417310d1adcf7448b
Patch
https://git.kernel.org/stable/c/7caaae233a55e167063f4cfa3385b1a04c8bbecb
Patch
https://git.kernel.org/stable/c/7ce02d52548b672795511c2cac8da6ec79ac8877
Patch
https://git.kernel.org/stable/c/d0284d974be46a0a06068f930c84039d540ae8ed
Patch