« Volver al listado

CVE-2026-93800

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()

If during relocation we fail in insert_dirty_subvol() because btrfs_update_reloc_root() returned an error, we will leave a root's reloc_root field pointing to a reloc root that was freed instead of NULL, resulting later in a use-after-free, or double free attempt during unmount.

The sequence of steps is this:

6) When unmounting the fs we end up calling:

Syzbot reported this with the following dmesg/syslog:

Detalles técnicos trazas, registros y código del informe original
1) During relocation the call to btrfs_update_reloc_root() in
   insert_dirty_subvol() fails, so insert_dirty_subvol() returns the
   error to merge_reloc_root() without adding the root to the list
   rc->dirty_subvol_roots;

2) Then merge_reloc_root() aborts the current transaction because
   insert_dirty_subvol() returned an error;

3) Up the call chain, merge_reloc_roots() gets the error, adds the
   reloc root for root X to the local reloc_roots list and jumps to the
   'out' label, where it calls free_reloc_roots() to free all the reloc
   roots in the local reloc_roots list. This frees the reloc root for
   root X;

4) We go up the call chain to relocate_block_group() which calls
   clean_dirty_subvols() to go over dirty roots and set their
   ->reloc_root field to NULL, but root X is not in the dirty_subvol_roots
   list, so its ->reloc_root still points to a reloc root;

5) Relocation finishes, with an error and a transaction abort, but the
   ->reloc_root field for root X still points to the reloc root that was
   freed in step 3;

     btrfs_free_fs_roots()
        btrfs_drop_and_free_fs_root()
           --> calls btrfs_put_root() against root X's ->reloc_root
               which is not NULL and points to the already freed
               reloc root in step 4 above

  Resulting in a use-after-free to a double free attempt.

   [  106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)
   [  106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure
   [  106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5
   [  106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.
   [  106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0
   [  106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure
   [  106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly
   [  106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure
   [  106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1
   [  106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30
   [  106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30
   [  106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409
   [  106.682946][ T5338] ==================================================================
   [  106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250
   [  106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338
   [  106.693173][ T5338]
   [  106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
   [  106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
   [  106.694300][ T5338] Call Trace:
   [  106.694308][ T5338]  <TASK>
   [  106.694314][ T5338]  dump_stack_lvl+0xe8/0x150
   [  106.694331][ T5338]  print_address_description+0x55/0x1e0
   [  106.694343][ T5338]  ? btrfs_put_root+0x2f/0x250
   [  106.694358][ T5338]  print_report+0x58/0x70
   [  106.
---truncated---

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93800",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f32b84d7c977e1906a4781b93b3c93090b6cd675",
              "lessThan": "5a247097c5f94b51ffc991b444d998ad6e85875f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "592fbcd50c99b8adf999a2a54f9245caff333139",
              "lessThan": "6372dd394ea907cd85a7a8063db320ec73dfaed0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "592fbcd50c99b8adf999a2a54f9245caff333139",
              "lessThan": "9f599d120b2b79d2d937c3935b7cdf2697514283",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "592fbcd50c99b8adf999a2a54f9245caff333139",
              "lessThan": "a01837ae174a2a968c245a30e6dd010f50eaf05d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "592fbcd50c99b8adf999a2a54f9245caff333139",
              "lessThan": "97a540d72ebcb21853d11f2a56782fe377f358e7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "592fbcd50c99b8adf999a2a54f9245caff333139",
              "lessThan": "fda1b6636ff1846f00643e791099db5564b547d9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "592fbcd50c99b8adf999a2a54f9245caff333139",
              "lessThan": "83201804efa4a5168be754e1dfc9b2faee760cac",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "aa18bc1ff8a51f082d5b3b6d07693797637b4028",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4cb0aea2e250eee35ccfac5f5395cd8f3238a9e5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.36",
              "lessThan": "5.10.271",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.11.20",
              "lessThan": "5.12",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.12.3",
              "lessThan": "5.13",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/btrfs/relocation.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/btrfs/relocation.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:12.870",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/5a247097c5f94b51ffc991b444d998ad6e85875f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6372dd394ea907cd85a7a8063db320ec73dfaed0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/83201804efa4a5168be754e1dfc9b2faee760cac",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/97a540d72ebcb21853d11f2a56782fe377f358e7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9f599d120b2b79d2d937c3935b7cdf2697514283",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a01837ae174a2a968c245a30e6dd010f50eaf05d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fda1b6636ff1846f00643e791099db5564b547d9",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()\n\nIf during relocation we fail in insert_dirty_subvol() because\nbtrfs_update_reloc_root() returned an error, we will leave a root's\nreloc_root field pointing to a reloc root that was freed instead of NULL,\nresulting later in a use-after-free, or double free attempt during\nunmount.\n\nThe sequence of steps is this:\n\n1) During relocation the call to btrfs_update_reloc_root() in\n   insert_dirty_subvol() fails, so insert_dirty_subvol() returns the\n   error to merge_reloc_root() without adding the root to the list\n   rc->dirty_subvol_roots;\n\n2) Then merge_reloc_root() aborts the current transaction because\n   insert_dirty_subvol() returned an error;\n\n3) Up the call chain, merge_reloc_roots() gets the error, adds the\n   reloc root for root X to the local reloc_roots list and jumps to the\n   'out' label, where it calls free_reloc_roots() to free all the reloc\n   roots in the local reloc_roots list. This frees the reloc root for\n   root X;\n\n4) We go up the call chain to relocate_block_group() which calls\n   clean_dirty_subvols() to go over dirty roots and set their\n   ->reloc_root field to NULL, but root X is not in the dirty_subvol_roots\n   list, so its ->reloc_root still points to a reloc root;\n\n5) Relocation finishes, with an error and a transaction abort, but the\n   ->reloc_root field for root X still points to the reloc root that was\n   freed in step 3;\n\n6) When unmounting the fs we end up calling:\n\n     btrfs_free_fs_roots()\n        btrfs_drop_and_free_fs_root()\n           --> calls btrfs_put_root() against root X's ->reloc_root\n               which is not NULL and points to the already freed\n               reloc root in step 4 above\n\n  Resulting in a use-after-free to a double free attempt.\n\nSyzbot reported this with the following dmesg/syslog:\n\n   [  106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)\n   [  106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure\n   [  106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5\n   [  106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.\n   [  106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0\n   [  106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure\n   [  106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly\n   [  106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure\n   [  106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1\n   [  106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30\n   [  106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30\n   [  106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409\n   [  106.682946][ T5338] ==================================================================\n   [  106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250\n   [  106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338\n   [  106.693173][ T5338]\n   [  106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)\n   [  106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n   [  106.694300][ T5338] Call Trace:\n   [  106.694308][ T5338]  <TASK>\n   [  106.694314][ T5338]  dump_stack_lvl+0xe8/0x150\n   [  106.694331][ T5338]  print_address_description+0x55/0x1e0\n   [  106.694343][ T5338]  ? btrfs_put_root+0x2f/0x250\n   [  106.694358][ T5338]  print_report+0x58/0x70\n   [  106.\n---truncated---"
    }
  ],
  "lastModified": "2026-10-03T11:17:49.673",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}