« Volver al listado

CVE-2026-68450

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

btrfs: free mapping node on duplicate reloc root insert

__add_reloc_root() allocates a mapping_node before inserting it into rc->reloc_root_tree. If rb_simple_insert() finds an existing entry, it returns the existing rb_node and leaves the newly allocated node unlinked.

The error path then returns -EEXIST without freeing the new node. Since the node was never inserted into reloc_root_tree, the later cleanup in put_reloc_control() cannot find it either.

Free the newly allocated node before returning -EEXIST.

The callers currently assert that -EEXIST should not happen, so this is a defensive cleanup for an unexpected duplicate insert path. If the path is ever reached, the local allocation should still be released.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-68450",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
              "lessThan": "29d9746812d8b7c37d594f484e994fd552c3ec33",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
              "lessThan": "b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
              "lessThan": "92bedc0455552b42ada1a1f42b0e3a8593cdfccc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
              "lessThan": "14a8be9428435ee17f17fae7991215c246b7fd43",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
              "lessThan": "797dc567146c7e3c4f8d9680e4fbc76e0a6d9151",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
              "lessThan": "ae0629ff9ccb836416ada129f4edc7efea6eaaad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "57a304cfd43b2b4a5b44b8f5dc026abb34183068",
              "lessThan": "6a8269b6459ed870a8156c106a0f597383907872",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/btrfs/relocation.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.148",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.101",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.42",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/btrfs/relocation.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-12T01:17:07.930",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/14a8be9428435ee17f17fae7991215c246b7fd43",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/29d9746812d8b7c37d594f484e994fd552c3ec33",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6a8269b6459ed870a8156c106a0f597383907872",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/797dc567146c7e3c4f8d9680e4fbc76e0a6d9151",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/92bedc0455552b42ada1a1f42b0e3a8593cdfccc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ae0629ff9ccb836416ada129f4edc7efea6eaaad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: free mapping node on duplicate reloc root insert\n\n__add_reloc_root() allocates a mapping_node before inserting it into\nrc->reloc_root_tree.  If rb_simple_insert() finds an existing entry, it\nreturns the existing rb_node and leaves the newly allocated node unlinked.\n\nThe error path then returns -EEXIST without freeing the new node.  Since\nthe node was never inserted into reloc_root_tree, the later cleanup in\nput_reloc_control() cannot find it either.\n\nFree the newly allocated node before returning -EEXIST.\n\nThe callers currently assert that -EEXIST should not happen, so this is a\ndefensive cleanup for an unexpected duplicate insert path.  If the path is\never reached, the local allocation should still be released."
    }
  ],
  "lastModified": "2026-08-19T17:20:50.807",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}