CVE-2026-89644
Received Received - Intake

Memory Leak in Linux Kernel Btrfs

Vulnerability report for CVE-2026-89644, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-21

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix extent map leak in NOCOW direct I/O write btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an extent map reference that must be dropped on all exit paths. For direct writes into a NOCOW range, btrfs_get_blocks_direct_write() keeps using that extent map and asks btrfs_create_dio_extent() to allocate the ordered extent. If that fails, for example because btrfs_alloc_ordered_extent() fails, the function returns the error without dropping the input extent map. The PREALLOC path avoided this by dropping the input extent map before replacing it with the newly created one. Check the error from btrfs_create_dio_extent() before replacing the map and drop the input extent map on failure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-21
Generated
2026-10-03
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a memory leak in the Btrfs file system when handling direct I/O writes to NOCOW (No Copy-On-Write) ranges. The issue occurs when an error happens during the creation of an ordered extent, causing the function to return without releasing an extent map reference. This leads to a resource leak.

Detection Guidance

This vulnerability is specific to the Linux kernel's Btrfs filesystem and does not have a direct network detection method. To detect it, check if your system is running a vulnerable kernel version. Use commands like 'uname -r' to see the kernel version and compare it against patched versions. Monitor Btrfs-related errors in system logs using 'dmesg | grep btrfs' or 'journalctl -u btrfs'.

Impact Analysis

The vulnerability could lead to memory exhaustion over time due to the leaked extent map references. This may cause system instability, crashes, or degraded performance, particularly in systems heavily using Btrfs with direct I/O operations.

Compliance Impact

This vulnerability is a memory leak in the Linux kernel's Btrfs filesystem during NOCOW direct I/O writes. It does not directly impact compliance with standards like GDPR or HIPAA, as those focus on data protection, privacy, and security controls rather than filesystem memory management issues.

Mitigation Strategies

Update your Linux kernel to the latest stable version that includes the fix for this vulnerability. If immediate updating is not possible, avoid using Btrfs NOCOW direct I/O writes as a temporary workaround. Monitor kernel security advisories for patches.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89644. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart