« Volver al listado

CVE-2026-98279

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

btrfs: handle lack of space when cleaning up verity items

When enable_verity() hits the qgroup limit, rollback_verity() needs its own metadata reservation. When the qgroup limit or lack of space refuses the rollback, the whole filesystem is forced read-only even though the qgroup limit was for one subvolume only. Also orphan cleanup at the next mount fails the same way, so the leftover items are never removed: with -EDQUOT the subvolume stays unreachable, and with -ENOSPC on a full filesystem the next read-write mount fails.

Start transactions with btrfs_start_transaction_fallback_global_rsv() in btrfs_orphan_cleanup(), drop_verity_items() and rollback_verity().

Leer descripción completaMostrar menos

Those calls only delete items and free the space in the end, so they may use the global reserve and skip the qgroup limit, which avoids -ENOSPC and -EDQUOT.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98279",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "146054090b0859b28fc39015c7704ccc3c3a347f",
              "lessThan": "4b7ecabd87dc40998fe7870d7975279649229a3b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "146054090b0859b28fc39015c7704ccc3c3a347f",
              "lessThan": "efa5780b84f066f419a667f6b9542368b2f62074",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "146054090b0859b28fc39015c7704ccc3c3a347f",
              "lessThan": "76bf149cd0298544631e756670b89c399c7acbca",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/btrfs/inode.c",
            "fs/btrfs/verity.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/btrfs/inode.c",
            "fs/btrfs/verity.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:17.783",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/4b7ecabd87dc40998fe7870d7975279649229a3b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/76bf149cd0298544631e756670b89c399c7acbca",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/efa5780b84f066f419a667f6b9542368b2f62074",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: handle lack of space when cleaning up verity items\n\nWhen enable_verity() hits the qgroup limit, rollback_verity() needs its\nown metadata reservation. When the qgroup limit or lack of space refuses\nthe rollback, the whole filesystem is forced read-only even though the\nqgroup limit was for one subvolume only. Also orphan cleanup at the next\nmount fails the same way, so the leftover items are never removed: with\n-EDQUOT the subvolume stays unreachable, and with -ENOSPC on a full\nfilesystem the next read-write mount fails.\n\nStart transactions with btrfs_start_transaction_fallback_global_rsv() in\nbtrfs_orphan_cleanup(), drop_verity_items() and rollback_verity(). Those\ncalls only delete items and free the space in the end, so they may use\nthe global reserve and skip the qgroup limit, which avoids -ENOSPC and\n-EDQUOT."
    }
  ],
  "lastModified": "2026-10-06T09:18:17.783",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}