5.5

CVE-2026-98082

btrfs: fix the possible bioc_list memory leak during error

In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix the possible bioc_list memory leak during error

There are two possible ways to leak bioc memory on
btrfs_ordered_extent::bioc_list:

- An error occurred for btrfs_insert_one_raid_extent()
  Then the function btrfs_insert_raid_extent() immediately return
  without freeing any bioc in the bioc_list.

- An ordered extent hit an IO error
  In that case the ordered extent will have BTRFS_ORDERED_IOERR set, and
  skip the call on btrfs_insert_raid_extent() completely.

Fix the problem by:

- Introduce a new helper, btrfs_cleanup_ordered_bioc_list()
  Which will remove all bioc from the bioc_list, and release the bioc.

- Call the above helper for btrfs_insert_raid_extent()
  So that the cleanup helper is always called no matter what.

- Call the above helper for btrfs_finish_one_ordered()
  This is called just before the final release on the ordered extent.

This was reported by Sashiko when reviewing another patch.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.6.130 < 6.6.158
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.111
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.53
Linux ≫ Linux Kernel Version >= 6.19 < 7.2.7
Linux ≫ Linux Kernel Version 7.3 Update rc1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.054
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://git.kernel.org/stable/c/83f0c973cffb184d019390ffdb5d31de5c85bc61
Patch
https://git.kernel.org/stable/c/1b4d4e890c2c85d0f6365b5a08c48b4bbf85deb0
Patch
https://git.kernel.org/stable/c/bb4da45766d16503821f167054db76b735d89e94
Patch
https://git.kernel.org/stable/c/afbe73778338e6d1ac8c4486fbdf33f0cc1f2624
Patch
https://git.kernel.org/stable/c/d043c43d2b4ebcd75ee7f907948ef2847306d6b2
Patch