Description
In the Linux kernel, the following vulnerability has been resolved:

btrfs: drop recovered reloc root refs on recovery failure

During relocation recovery, each fs root gets a reference to its relocation
root. If loading or adding a later root fails, or if the first transaction
commit fails, btrfs_recover_relocation() jumps to out_unset before
merge_reloc_roots() and clean_dirty_subvols().

put_reloc_control() drops the list-owned relocation root references, but it
does not clear fs_root->reloc_root or drop the references owned by those
pointers. Mount cleanup only drops them when BTRFS_FS_ERROR is set, so an
error such as -ENOMEM while processing a later root can leave references
behind.

Keep temporary references to the fs roots associated during recovery. On
failure, clear their reloc_root pointers and drop the corresponding
references. Once the first transaction commit succeeds, drop only the
temporary fs root references and let the normal merge and cleanup paths
handle the relocation roots.

Fault injection on a pending-relocation image confirmed the cleanup gap.
With an injected first-commit failure, 25 fs roots had reloc_root set with
fs_error=0. With this fix, the same failure path drops that count to 0
before mount fails.
Published: 2026-09-11
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Apply Patch
AI Analysis

Impact

The flaw in the Linux kernel’s btrfs subsystem prevents proper cleanup of relocation root references when a recovery operation aborts. When a relocation recovery exits early because of an error, the code that should drop temporary pointers is bypassed, leaving fs_root structures that still point to relocation roots. These dangling references can trigger a crash or other instability when subsequent filesystem operations use them. The weakness is an example of CWE‑911: Improper Resource Cleanup.

Affected Systems

All Linux kernel implementations that include btrfs support are affected when the missing cleanup logic has not been applied. The specific version range is not listed, so any kernel prior to the patch that added the missing cleanup is susceptible. Mount or format btrfs filesystems may experience the issue.

Risk and Exploitability

The CVSS score of 4.4 reflects moderate severity, largely because the flaw requires the recovery path to be invoked and does not provide an easy remote entry point. The EPSS score of less than 1% indicates that exploitation in the wild is rare. The CVE is not listed in the CISA KEV catalog. Attackers would need to trigger a btrfs relocation recovery—typically by mounting an affected volume or forcing the kernel to recover a corrupt image—which generally requires local privileged execution or a compromised root user. The likely attack vector is thus local privilege escalation or a root‑level action rather than a remote exploit.

Generated by OpenCVE AI on September 15, 2026 at 21:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the btrfs relocation cleanup patch
  • If an update is not immediately available, avoid mounting or creating btrfs filesystems until the patch is applied
  • Reboot the system after applying the kernel update to ensure the patched code is active

Generated by OpenCVE AI on September 15, 2026 at 21:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-911
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: btrfs: drop recovered reloc root refs on recovery failure During relocation recovery, each fs root gets a reference to its relocation root. If loading or adding a later root fails, or if the first transaction commit fails, btrfs_recover_relocation() jumps to out_unset before merge_reloc_roots() and clean_dirty_subvols(). put_reloc_control() drops the list-owned relocation root references, but it does not clear fs_root->reloc_root or drop the references owned by those pointers. Mount cleanup only drops them when BTRFS_FS_ERROR is set, so an error such as -ENOMEM while processing a later root can leave references behind. Keep temporary references to the fs roots associated during recovery. On failure, clear their reloc_root pointers and drop the corresponding references. Once the first transaction commit succeeds, drop only the temporary fs root references and let the normal merge and cleanup paths handle the relocation roots. Fault injection on a pending-relocation image confirmed the cleanup gap. With an injected first-commit failure, 25 fs roots had reloc_root set with fs_error=0. With this fix, the same failure path drops that count to 0 before mount fails.
Title btrfs: drop recovered reloc root refs on recovery failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:45:37.016Z

Reserved: 2026-09-11T19:38:34.741Z

Link: CVE-2026-89645

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:50.350

Modified: 2026-09-11T20:19:50.350

Link: CVE-2026-89645

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:45:37Z

Links: CVE-2026-89645 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T21:00:17Z

Weaknesses
  • CWE-911

    Improper Update of Reference Count