« Volver al listado

CVE-2026-98080

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

btrfs: do not force reloc root creation during qgroup_account_snapshot()

[BUG] When running btrfs/252 with quota enabled through MKFS_OPTIONS="-O quota", it has a high chance to trigger the following kernel warning and flips the fs RO:

[CAUSE] The above error is showing that there is a tree reference to a metadata extent that is no longer there.

With "ref_verify" mount option (requires CONFIG_BTRFS_DEBUG), there is some extra debug output:

---truncated---

Detalles técnicos trazas, registros y código del informe original
  BTRFS info (device dm-2): relocating block group 30408704 flags metadata|dup
  ------------[ cut here ]------------
  WARNING: fs/btrfs/extent-tree.c:879 at lookup_inline_extent_backref+0x74b/0x960 [btrfs], CPU#4: btrfs/2173
  CPU: 4 UID: 0 PID: 2173 Comm: btrfs Not tainted 7.2.0-rc6-custom+ #457 PREEMPT(full)  3adc6528fb66f7a55fe1095385818e742f200aab
  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022
  RIP: 0010:lookup_inline_extent_backref+0x74b/0x960 [btrfs]
  Call Trace:
   <TASK>
   insert_inline_extent_backref+0x7c/0x160 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   __btrfs_inc_extent_ref+0xa9/0x270 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   __btrfs_run_delayed_refs+0x4af/0x11c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_run_delayed_refs+0x9d/0xf0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   create_pending_snapshot+0x39d/0xf00 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   create_pending_snapshots+0x9b/0xc0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_commit_transaction+0x280/0xeb0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   prepare_to_relocate+0x147/0x200 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   relocate_block_group+0x6b/0x5e0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_relocate_block_group+0x92c/0x2380 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_relocate_chunk+0x3f/0x1a0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_balance+0xa2c/0x19c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   btrfs_ioctl+0x2839/0x2d30 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]
   __x64_sys_ioctl+0x416/0x9a0
   do_syscall_64+0xe1/0x790
   entry_SYSCALL_64_after_hwframe+0x4b/0x53
   </TASK>
  ---[ end trace 0000000000000000 ]---
  BTRFS info (device dm-2): leaf 4593991680 gen 233 total ptrs 175 free space 5953 owner 2
  BTRFS info (device dm-2): refs 3 lock_owner 2173 current 2173
  	item 0 key (166772736 METADATA_ITEM 1) itemoff 16250 itemsize 33
  		extent refs 1 gen 222 flags 2
  		ref#0: tree block backref root 266
         [ Skip the tree dump ]
  	item 174 key (263225344 METADATA_ITEM 0) itemoff 10328 itemsize 33
  		extent refs 1 gen 162 flags 258
  		ref#0: tree block backref root 267
  BTRFS error (device dm-2): extent item not found for insert, bytenr 179847168 num_bytes 16384 parent 4594335744 root_objectid 273 owner 0 offset 0
  BTRFS error (device dm-2): failed to run delayed ref for logical 179847168 num_bytes 16384 type 182 action 1 ref_mod 1: -117

  BTRFS error (device dm-2): dumping block entry [180961280 16384], num_refs 0, metadata 1, from disk 0
  BTRFS error (device dm-2):   root entry 256, num_refs 18446744073709551615
  BTRFS error (device dm-2):   root entry 273, num_refs 18446744073709551615
  BTRFS error (device dm-2):   Ref action 3, root 273, ref_root 273, parent 0, owner 0, offset 0, num_refs 1
     btrfs_force_cow_block+0x129/0x7d0 [btrfs]
     btrfs_cow_block+0x10a/0x250 [btrfs]
     btrfs_search_slot+0x5eb/0xf40 [btrfs]
     btrfs_insert_empty_items+0x3a/0x70 [btrfs]
     insert_with_overflow+0x53/0x130 [btrfs]
     btrfs_insert_dir_item+0x125/0x290 [btrfs]
     btrfs_add_link+0xaa/0x410 [btrfs]
     btrfs_rename+0x5ea/0xcd0 [btrfs]
     btrfs_rename2+0x28/0x60 [btrfs]
     vfs_rename+0x5b2/0xe10
     filename_renameat2+0x244/0x430
     __x64_sys_rename+0x48/0x70
     do_syscall_64+0xe1/0x790
     entry_SYSCALL_64_after_hwframe+0x4b/0x53

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L/PR:L) sin interacción que causa denegación de servicio (flip a RO, kernel warning). El acceso local con privilegios de usuario puede provocar bloqueo del sistema de archivos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98080",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4d31778aa2fa342f5f92ca4025b293a1729161d1",
              "lessThan": "d0284d974be46a0a06068f930c84039d540ae8ed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d31778aa2fa342f5f92ca4025b293a1729161d1",
              "lessThan": "21bd77c132f18dc21c6fcdf417310d1adcf7448b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d31778aa2fa342f5f92ca4025b293a1729161d1",
              "lessThan": "7ce02d52548b672795511c2cac8da6ec79ac8877",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d31778aa2fa342f5f92ca4025b293a1729161d1",
              "lessThan": "7caaae233a55e167063f4cfa3385b1a04c8bbecb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d31778aa2fa342f5f92ca4025b293a1729161d1",
              "lessThan": "c4c78768d1a8ceb713693cc5524acbe984c31f3c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d31778aa2fa342f5f92ca4025b293a1729161d1",
              "lessThan": "203cbfb4fba590bd9b08bd36fa6d05b5d28923bf",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d31778aa2fa342f5f92ca4025b293a1729161d1",
              "lessThan": "b5d5ab5a715001dd937c920ef8c5688fd4999ba1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4d31778aa2fa342f5f92ca4025b293a1729161d1",
              "lessThan": "cacf35832292997018837e484283f95a9301ebf5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "204bfcda824428b3a298eae8e87875bbd435a3c1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1f586802bb18892d2a6eb7d31d7fed78946d21a1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4.14.45",
              "lessThan": "4.15",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.16.13",
              "lessThan": "4.17",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/btrfs/transaction.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.17"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.17",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/btrfs/transaction.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:37.417",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/203cbfb4fba590bd9b08bd36fa6d05b5d28923bf",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/21bd77c132f18dc21c6fcdf417310d1adcf7448b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7caaae233a55e167063f4cfa3385b1a04c8bbecb",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7ce02d52548b672795511c2cac8da6ec79ac8877",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b5d5ab5a715001dd937c920ef8c5688fd4999ba1",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c4c78768d1a8ceb713693cc5524acbe984c31f3c",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cacf35832292997018837e484283f95a9301ebf5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d0284d974be46a0a06068f930c84039d540ae8ed",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-672"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not force reloc root creation during qgroup_account_snapshot()\n\n[BUG]\nWhen running btrfs/252 with quota enabled through MKFS_OPTIONS=\"-O quota\",\nit has a high chance to trigger the following kernel warning and flips\nthe fs RO:\n\n  BTRFS info (device dm-2): relocating block group 30408704 flags metadata|dup\n  ------------[ cut here ]------------\n  WARNING: fs/btrfs/extent-tree.c:879 at lookup_inline_extent_backref+0x74b/0x960 [btrfs], CPU#4: btrfs/2173\n  CPU: 4 UID: 0 PID: 2173 Comm: btrfs Not tainted 7.2.0-rc6-custom+ #457 PREEMPT(full)  3adc6528fb66f7a55fe1095385818e742f200aab\n  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022\n  RIP: 0010:lookup_inline_extent_backref+0x74b/0x960 [btrfs]\n  Call Trace:\n   <TASK>\n   insert_inline_extent_backref+0x7c/0x160 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   __btrfs_inc_extent_ref+0xa9/0x270 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   __btrfs_run_delayed_refs+0x4af/0x11c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   btrfs_run_delayed_refs+0x9d/0xf0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   create_pending_snapshot+0x39d/0xf00 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   create_pending_snapshots+0x9b/0xc0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   btrfs_commit_transaction+0x280/0xeb0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   prepare_to_relocate+0x147/0x200 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   relocate_block_group+0x6b/0x5e0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   btrfs_relocate_block_group+0x92c/0x2380 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   btrfs_relocate_chunk+0x3f/0x1a0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   btrfs_balance+0xa2c/0x19c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   btrfs_ioctl+0x2839/0x2d30 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72]\n   __x64_sys_ioctl+0x416/0x9a0\n   do_syscall_64+0xe1/0x790\n   entry_SYSCALL_64_after_hwframe+0x4b/0x53\n   </TASK>\n  ---[ end trace 0000000000000000 ]---\n  BTRFS info (device dm-2): leaf 4593991680 gen 233 total ptrs 175 free space 5953 owner 2\n  BTRFS info (device dm-2): refs 3 lock_owner 2173 current 2173\n  \titem 0 key (166772736 METADATA_ITEM 1) itemoff 16250 itemsize 33\n  \t\textent refs 1 gen 222 flags 2\n  \t\tref#0: tree block backref root 266\n         [ Skip the tree dump ]\n  \titem 174 key (263225344 METADATA_ITEM 0) itemoff 10328 itemsize 33\n  \t\textent refs 1 gen 162 flags 258\n  \t\tref#0: tree block backref root 267\n  BTRFS error (device dm-2): extent item not found for insert, bytenr 179847168 num_bytes 16384 parent 4594335744 root_objectid 273 owner 0 offset 0\n  BTRFS error (device dm-2): failed to run delayed ref for logical 179847168 num_bytes 16384 type 182 action 1 ref_mod 1: -117\n\n[CAUSE]\nThe above error is showing that there is a tree reference to a metadata\nextent that is no longer there.\n\nWith \"ref_verify\" mount option (requires CONFIG_BTRFS_DEBUG), there is\nsome extra debug output:\n\n  BTRFS error (device dm-2): dumping block entry [180961280 16384], num_refs 0, metadata 1, from disk 0\n  BTRFS error (device dm-2):   root entry 256, num_refs 18446744073709551615\n  BTRFS error (device dm-2):   root entry 273, num_refs 18446744073709551615\n  BTRFS error (device dm-2):   Ref action 3, root 273, ref_root 273, parent 0, owner 0, offset 0, num_refs 1\n     btrfs_force_cow_block+0x129/0x7d0 [btrfs]\n     btrfs_cow_block+0x10a/0x250 [btrfs]\n     btrfs_search_slot+0x5eb/0xf40 [btrfs]\n     btrfs_insert_empty_items+0x3a/0x70 [btrfs]\n     insert_with_overflow+0x53/0x130 [btrfs]\n     btrfs_insert_dir_item+0x125/0x290 [btrfs]\n     btrfs_add_link+0xaa/0x410 [btrfs]\n     btrfs_rename+0x5ea/0xcd0 [btrfs]\n     btrfs_rename2+0x28/0x60 [btrfs]\n     vfs_rename+0x5b2/0xe10\n     filename_renameat2+0x244/0x430\n     __x64_sys_rename+0x48/0x70\n     do_syscall_64+0xe1/0x790\n     entry_SYSCALL_64_after_hwframe+0x4b/0x53\n \n---truncated---"
    }
  ],
  "lastModified": "2026-10-06T17:00:55.290",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D700D41-4E8D-4E37-8603-F71095BDF7CF",
              "versionEndExcluding": "4.15",
              "versionStartIncluding": "4.14.45"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "030C9B37-5360-4849-87C4-2E18CCB2174E",
              "versionEndExcluding": "5.10.271",
              "versionStartIncluding": "4.16.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5EFABC8-89EB-4EE7-9EE1-A9A30E730AFC",
              "versionEndExcluding": "5.15.222",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D92935F-58C8-4A77-A806-0274F6C958F0",
              "versionEndExcluding": "6.1.189",
              "versionStartIncluding": "6.0"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "575D98F4-AE0C-4D1F-91BC-CD1C75F0FED0",
              "versionEndExcluding": "6.6.158",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47BC31C9-3D9E-4B96-B5F8-291D6AD55D81",
              "versionEndExcluding": "6.12.111",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7561AABB-6D5A-4324-BC66-C6C6B012AFD8",
              "versionEndExcluding": "6.18.53",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19917B2D-B4B2-4416-A482-9C7C4929A921",
              "versionEndExcluding": "7.2.7",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.3:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11E35E1B-5DB4-4AB9-9706-CD73B799EADF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}