Description
In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix extent map leak in NOCOW direct I/O write

btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an
extent map reference that must be dropped on all exit paths.

For direct writes into a NOCOW range, btrfs_get_blocks_direct_write()
keeps using that extent map and asks btrfs_create_dio_extent() to
allocate the ordered extent. If that fails, for example because
btrfs_alloc_ordered_extent() fails, the function returns the error
without dropping the input extent map. The PREALLOC path avoided this by
dropping the input extent map before replacing it with the newly created
one.

Check the error from btrfs_create_dio_extent() before replacing the
map and drop the input extent map on failure.
Published: 2026-09-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion (Denial of Service)
Action: Patch Immediately
AI Analysis

Impact

A path in the Btrfs file‑system code a direct write into a NOCOW range fails. The reference is never released on the error return path, causing memory objects to persist and accumulate. Repeated failures can lead to kernel resource exhaustion, potentially triggering memory pressure, system instability, or crash.

Affected Systems

All Linux kernel distributions that ship unpatched Btrfs code are affected. The specific version ranges are not enumerated, so any kernel before the commit that introduced the fix may be vulnerable. The impact applies to systems that use Btrfs filesystems containing NOCOW ranges.

Risk and Exploitability

The CVSS score of 5.5 denotes moderate severity, and the EPSS of <1% indicates a very low probability of exploitation in the wild. No public exploitation is reported and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires local or elevated privileges to initiate direct I/O writes into a NOCOW range, a capability typically available to root or processes with CAP_DAC_OVERRIDE. An attacker would need the ability to trigger repeated write failures along the vulnerable path to exhaust kernel resources.

Generated by OpenCVE AI on September 15, 2026 at 21:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that includes the Btrfs extent map leak fix commit.
  • If a kernel upgrade is not immediately possible, avoid direct I/O on NOCOW ranges; use buffered writes instead or remount the filesystem with the NOCOW option disabled if direct I/O is not required.
  • Monitor system logs and memory usage for signs of kernel instability or resource exhaustion, and restrict write activity until the patch is applied.

Generated by OpenCVE AI on September 15, 2026 at 21:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O write btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an extent map reference that must be dropped on all exit paths. For direct writes into a NOCOW range, btrfs_get_blocks_direct_write() keeps using that extent map and asks btrfs_create_dio_extent() to allocate the ordered extent. If that fails, for example because btrfs_alloc_ordered_extent() fails, the function returns the error without dropping the input extent map. The PREALLOC path avoided this by dropping the input extent map before replacing it with the newly created one. Check the error from btrfs_create_dio_extent() before replacing the map and drop the input extent map on failure.
Title btrfs: fix extent map leak in NOCOW direct I/O write
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:39.048Z

Reserved: 2026-09-11T19:38:34.741Z

Link: CVE-2026-89644

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:50.223

Modified: 2026-09-21T14:17:24.403

Link: CVE-2026-89644

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:36Z

Links: CVE-2026-89644 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:15:14Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime