CVE-2026-93800
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()
If during relocation we fail in insert_dirty_subvol() because btrfs_update_reloc_root() returned an error, we will leave a root's reloc_root field pointing to a reloc root that was freed instead of NULL, resulting later in a use-after-free, or double free attempt during unmount.
The sequence of steps is this:
6) When unmounting the fs we end up calling:
Syzbot reported this with the following dmesg/syslog:
Detalles técnicos trazas, registros y código del informe original
1) During relocation the call to btrfs_update_reloc_root() in
insert_dirty_subvol() fails, so insert_dirty_subvol() returns the
error to merge_reloc_root() without adding the root to the list
rc->dirty_subvol_roots;
2) Then merge_reloc_root() aborts the current transaction because
insert_dirty_subvol() returned an error;
3) Up the call chain, merge_reloc_roots() gets the error, adds the
reloc root for root X to the local reloc_roots list and jumps to the
'out' label, where it calls free_reloc_roots() to free all the reloc
roots in the local reloc_roots list. This frees the reloc root for
root X;
4) We go up the call chain to relocate_block_group() which calls
clean_dirty_subvols() to go over dirty roots and set their
->reloc_root field to NULL, but root X is not in the dirty_subvol_roots
list, so its ->reloc_root still points to a reloc root;
5) Relocation finishes, with an error and a transaction abort, but the
->reloc_root field for root X still points to the reloc root that was
freed in step 3;
btrfs_free_fs_roots()
btrfs_drop_and_free_fs_root()
--> calls btrfs_put_root() against root X's ->reloc_root
which is not NULL and points to the already freed
reloc root in step 4 above
Resulting in a use-after-free to a double free attempt.
[ 106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)
[ 106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure
[ 106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5
[ 106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.
[ 106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0
[ 106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure
[ 106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly
[ 106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure
[ 106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1
[ 106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30
[ 106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30
[ 106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409
[ 106.682946][ T5338] ==================================================================
[ 106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250
[ 106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338
[ 106.693173][ T5338]
[ 106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
[ 106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 106.694300][ T5338] Call Trace:
[ 106.694308][ T5338] <TASK>
[ 106.694314][ T5338] dump_stack_lvl+0xe8/0x150
[ 106.694331][ T5338] print_address_description+0x55/0x1e0
[ 106.694343][ T5338] ? btrfs_put_root+0x2f/0x250
[ 106.694358][ T5338] print_report+0x58/0x70
[ 106.
---truncated---CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/5a247097c5f94b51ffc991b444d998ad6e85875f
- https://git.kernel.org/stable/c/6372dd394ea907cd85a7a8063db320ec73dfaed0
- https://git.kernel.org/stable/c/83201804efa4a5168be754e1dfc9b2faee760cac
- https://git.kernel.org/stable/c/97a540d72ebcb21853d11f2a56782fe377f358e7
- https://git.kernel.org/stable/c/9f599d120b2b79d2d937c3935b7cdf2697514283
- https://git.kernel.org/stable/c/a01837ae174a2a968c245a30e6dd010f50eaf05d
- https://git.kernel.org/stable/c/fda1b6636ff1846f00643e791099db5564b547d9
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93800",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "f32b84d7c977e1906a4781b93b3c93090b6cd675",
"lessThan": "5a247097c5f94b51ffc991b444d998ad6e85875f",
"versionType": "git"
},
{
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"lessThan": "6372dd394ea907cd85a7a8063db320ec73dfaed0",
"versionType": "git"
},
{
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"lessThan": "9f599d120b2b79d2d937c3935b7cdf2697514283",
"versionType": "git"
},
{
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"lessThan": "a01837ae174a2a968c245a30e6dd010f50eaf05d",
"versionType": "git"
},
{
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"lessThan": "97a540d72ebcb21853d11f2a56782fe377f358e7",
"versionType": "git"
},
{
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"lessThan": "fda1b6636ff1846f00643e791099db5564b547d9",
"versionType": "git"
},
{
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"lessThan": "83201804efa4a5168be754e1dfc9b2faee760cac",
"versionType": "git"
},
{
"status": "affected",
"version": "aa18bc1ff8a51f082d5b3b6d07693797637b4028",
"versionType": "git"
},
{
"status": "affected",
"version": "4cb0aea2e250eee35ccfac5f5395cd8f3238a9e5",
"versionType": "git"
},
{
"status": "affected",
"version": "5.10.36",
"lessThan": "5.10.271",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.11.20",
"lessThan": "5.12",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.12.3",
"lessThan": "5.13",
"versionType": "semver"
}
],
"programFiles": [
"fs/btrfs/relocation.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"fs/btrfs/relocation.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-24T17:17:12.870",
"references": [
{
"url": "https://git.kernel.org/stable/c/5a247097c5f94b51ffc991b444d998ad6e85875f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6372dd394ea907cd85a7a8063db320ec73dfaed0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/83201804efa4a5168be754e1dfc9b2faee760cac",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/97a540d72ebcb21853d11f2a56782fe377f358e7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9f599d120b2b79d2d937c3935b7cdf2697514283",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a01837ae174a2a968c245a30e6dd010f50eaf05d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fda1b6636ff1846f00643e791099db5564b547d9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()\n\nIf during relocation we fail in insert_dirty_subvol() because\nbtrfs_update_reloc_root() returned an error, we will leave a root's\nreloc_root field pointing to a reloc root that was freed instead of NULL,\nresulting later in a use-after-free, or double free attempt during\nunmount.\n\nThe sequence of steps is this:\n\n1) During relocation the call to btrfs_update_reloc_root() in\n insert_dirty_subvol() fails, so insert_dirty_subvol() returns the\n error to merge_reloc_root() without adding the root to the list\n rc->dirty_subvol_roots;\n\n2) Then merge_reloc_root() aborts the current transaction because\n insert_dirty_subvol() returned an error;\n\n3) Up the call chain, merge_reloc_roots() gets the error, adds the\n reloc root for root X to the local reloc_roots list and jumps to the\n 'out' label, where it calls free_reloc_roots() to free all the reloc\n roots in the local reloc_roots list. This frees the reloc root for\n root X;\n\n4) We go up the call chain to relocate_block_group() which calls\n clean_dirty_subvols() to go over dirty roots and set their\n ->reloc_root field to NULL, but root X is not in the dirty_subvol_roots\n list, so its ->reloc_root still points to a reloc root;\n\n5) Relocation finishes, with an error and a transaction abort, but the\n ->reloc_root field for root X still points to the reloc root that was\n freed in step 3;\n\n6) When unmounting the fs we end up calling:\n\n btrfs_free_fs_roots()\n btrfs_drop_and_free_fs_root()\n --> calls btrfs_put_root() against root X's ->reloc_root\n which is not NULL and points to the already freed\n reloc root in step 4 above\n\n Resulting in a use-after-free to a double free attempt.\n\nSyzbot reported this with the following dmesg/syslog:\n\n [ 106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)\n [ 106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure\n [ 106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5\n [ 106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.\n [ 106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0\n [ 106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure\n [ 106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly\n [ 106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure\n [ 106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1\n [ 106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30\n [ 106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30\n [ 106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409\n [ 106.682946][ T5338] ==================================================================\n [ 106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250\n [ 106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338\n [ 106.693173][ T5338]\n [ 106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)\n [ 106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n [ 106.694300][ T5338] Call Trace:\n [ 106.694308][ T5338] <TASK>\n [ 106.694314][ T5338] dump_stack_lvl+0xe8/0x150\n [ 106.694331][ T5338] print_address_description+0x55/0x1e0\n [ 106.694343][ T5338] ? btrfs_put_root+0x2f/0x250\n [ 106.694358][ T5338] print_report+0x58/0x70\n [ 106.\n---truncated---"
}
],
"lastModified": "2026-10-03T11:17:49.673",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}