Description
In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix transaction use-after-free in raid stripe insertion

If allocation of a RAID stripe extent fails,
btrfs_insert_one_raid_extent() aborts and ends the transaction before
returning -ENOMEM.

btrfs_finish_one_ordered(), the production caller through
btrfs_insert_raid_extent(), still owns the transaction handle. It handles
the error by aborting the transaction and then reaches the common exit
path, which ends the transaction again.

The premature end can free the handle and drop its transaction reference.
Transaction cleanup can then free the transaction before the caller's
second abort accesses the handle and transaction, resulting in
use-after-free.

Keep the abort at the failure site, but let the caller's common exit path
end the transaction once, after it has finished using both objects.
Published: 2026-09-25
Score: 7 High
EPSS: n/a
KEV: No
Impact: Kernel memory corruption potentially leading to privilege escalation or denial of service
Action: Apply patch
AI Analysis

Impact

This flaw in the Btrfs filesystem occurs when a RAID stripe extent allocation fails. The insert function aborts the transaction before returning, yet the caller still holds a reference to the transaction handle. Because the transaction cleanup frees the handle and then the caller aborts again, the code uses a transaction that has already been freed. This use‑after‑free can corrupt kernel memory, allowing an attacker to overwrite privileged structures or crash the system, which may lead to privilege escalation or denial of service.

Affected Systems

The vulnerability is present in the Linux kernel’s Btrfs implementation. Any kernel built from the source tree that includes the legacy btrfs raid stripe insertion logic is potentially vulnerable. The issue is tied specifically to filesystems configured with Btrfs RAID, so non‑RAID configurations are not affected.

Risk and Exploitability

The flaw is a use‑after‑free within kernel space; exploitation would require the attacker to trigger a stripe insertion failure, typically through manipulation of Btrfs structures or file operations. The public CVSS score is not provided and EPSS data is unavailable, indicating that the exploitation probability is uncertain. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widely known exploits yet. Nevertheless, because it can lead to kernel memory corruption and potentially privilege escalation or crash, the risk level is high. The attack vector is inferred to be local, requiring access to a privileged user manipulating a Btrfs RAID file system.

Generated by OpenCVE AI on September 25, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to the latest stable release that incorporates the Btrfs transaction fix.
  • If the system does not require Btrfs RAID, disable the RAID feature or convert the filesystem to a non‑RAID mode to remove the vulnerable code path.
  • Enable kernel hardening options such as KASLR and SELinux, and monitor system logs for Oops or BUG entries that may indicate an accidental reactivation of the flaw.

Generated by OpenCVE AI on September 25, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 25 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Fri, 25 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: btrfs: fix transaction use-after-free in raid stripe insertion If allocation of a RAID stripe extent fails, btrfs_insert_one_raid_extent() aborts and ends the transaction before returning -ENOMEM. btrfs_finish_one_ordered(), the production caller through btrfs_insert_raid_extent(), still owns the transaction handle. It handles the error by aborting the transaction and then reaches the common exit path, which ends the transaction again. The premature end can free the handle and drop its transaction reference. Transaction cleanup can then free the transaction before the caller's second abort accesses the handle and transaction, resulting in use-after-free. Keep the abort at the failure site, but let the caller's common exit path end the transaction once, after it has finished using both objects.
Title btrfs: fix transaction use-after-free in raid stripe insertion
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-25T14:42:03.354Z

Reserved: 2026-09-25T10:19:56.075Z

Link: CVE-2026-98083

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-25T11:17:37.860

Modified: 2026-09-25T15:18:05.703

Link: CVE-2026-98083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T16:15:16Z

Weaknesses