« Volver al listado

CVE-2026-98081

Estado: En análisisSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

btrfs: zoned: finish active block group cleanup if call_zone_finish() fails

do_zone_finish() clears BLOCK_GROUP_FLAG_ZONE_IS_ACTIVE before finishing the zones. If call_zone_finish() then fails it returned early, leaving the now inactive block group on fs_info->zone_active_bgs, leaking its reference, the BTRFS_FS_NEED_ZONE_FINISH waiters are never woken, and as its alloc_offset equals the zone capacity btrfs_zone_finish_one_bg() keeps selecting it, spinning btrfs_zoned_activate_one_bg().

Fall through to the cleanup on failure too and return the error, but keep the block group read-only as its zones are left inconsistent.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98081",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d70cbdda75da3f258118a558c087157e073229fb",
              "lessThan": "36b9cdab44848f25879ca625275c92b007f84653",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d70cbdda75da3f258118a558c087157e073229fb",
              "lessThan": "40370f02a1ca3760f8925ffcbe76eb4d91ea758d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d70cbdda75da3f258118a558c087157e073229fb",
              "lessThan": "e1b168a53174b385e3548bfbd079513b22ac240c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d70cbdda75da3f258118a558c087157e073229fb",
              "lessThan": "a18a6b93a2843b9d103d3456bbd4b3f90282a379",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/btrfs/zoned.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/btrfs/zoned.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:37.573",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/36b9cdab44848f25879ca625275c92b007f84653",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/40370f02a1ca3760f8925ffcbe76eb4d91ea758d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a18a6b93a2843b9d103d3456bbd4b3f90282a379",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e1b168a53174b385e3548bfbd079513b22ac240c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: finish active block group cleanup if call_zone_finish() fails\n\ndo_zone_finish() clears BLOCK_GROUP_FLAG_ZONE_IS_ACTIVE before finishing\nthe zones. If call_zone_finish() then fails it returned early, leaving the\nnow inactive block group on fs_info->zone_active_bgs, leaking its\nreference, the BTRFS_FS_NEED_ZONE_FINISH waiters are never woken, and as\nits alloc_offset equals the zone capacity btrfs_zone_finish_one_bg() keeps\nselecting it, spinning btrfs_zoned_activate_one_bg().\n\nFall through to the cleanup on failure too and return the error, but keep\nthe block group read-only as its zones are left inconsistent."
    }
  ],
  "lastModified": "2026-09-30T14:10:59.253",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}