CVE-2026-89644
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix extent map leak in NOCOW direct I/O write
btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an extent map reference that must be dropped on all exit paths.
For direct writes into a NOCOW range, btrfs_get_blocks_direct_write() keeps using that extent map and asks btrfs_create_dio_extent() to allocate the ordered extent. If that fails, for example because btrfs_alloc_ordered_extent() fails, the function returns the error without dropping the input extent map. The PREALLOC path avoided this by dropping the input extent map before replacing it with the newly created one.
Leer descripción completaMostrar menos
Check the error from btrfs_create_dio_extent() before replacing the map and drop the input extent map on failure.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-89644",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5f9a8a51d8b95505d8de8b7191ae2ed8c504d4af",
"lessThan": "b7c873765875645b11503f94c9bae2ca80127375",
"versionType": "git"
},
{
"status": "affected",
"version": "5f9a8a51d8b95505d8de8b7191ae2ed8c504d4af",
"lessThan": "f42efd634c0ae7ba0ce2fc5e30e291b0803b0ae2",
"versionType": "git"
},
{
"status": "affected",
"version": "5f9a8a51d8b95505d8de8b7191ae2ed8c504d4af",
"lessThan": "05a1a816eef8b3e4332620a64fc8cf45c4eb5c0d",
"versionType": "git"
},
{
"status": "affected",
"version": "5f9a8a51d8b95505d8de8b7191ae2ed8c504d4af",
"lessThan": "3f950867c307c5413d628a153ac44915bd117ffd",
"versionType": "git"
}
],
"programFiles": [
"fs/btrfs/direct-io.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.7"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.7",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/btrfs/direct-io.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:50.223",
"references": [
{
"url": "https://git.kernel.org/stable/c/05a1a816eef8b3e4332620a64fc8cf45c4eb5c0d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3f950867c307c5413d628a153ac44915bd117ffd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b7c873765875645b11503f94c9bae2ca80127375",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f42efd634c0ae7ba0ce2fc5e30e291b0803b0ae2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix extent map leak in NOCOW direct I/O write\n\nbtrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an\nextent map reference that must be dropped on all exit paths.\n\nFor direct writes into a NOCOW range, btrfs_get_blocks_direct_write()\nkeeps using that extent map and asks btrfs_create_dio_extent() to\nallocate the ordered extent. If that fails, for example because\nbtrfs_alloc_ordered_extent() fails, the function returns the error\nwithout dropping the input extent map. The PREALLOC path avoided this by\ndropping the input extent map before replacing it with the newly created\none.\n\nCheck the error from btrfs_create_dio_extent() before replacing the\nmap and drop the input extent map on failure."
}
],
"lastModified": "2026-09-21T14:17:24.403",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}