CVE-2026-89645
Received Received - Intake

Memory Leak in Linux Kernel Btrfs Filesystem

Vulnerability report for CVE-2026-89645, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: drop recovered reloc root refs on recovery failure During relocation recovery, each fs root gets a reference to its relocation root. If loading or adding a later root fails, or if the first transaction commit fails, btrfs_recover_relocation() jumps to out_unset before merge_reloc_roots() and clean_dirty_subvols(). put_reloc_control() drops the list-owned relocation root references, but it does not clear fs_root->reloc_root or drop the references owned by those pointers. Mount cleanup only drops them when BTRFS_FS_ERROR is set, so an error such as -ENOMEM while processing a later root can leave references behind. Keep temporary references to the fs roots associated during recovery. On failure, clear their reloc_root pointers and drop the corresponding references. Once the first transaction commit succeeds, drop only the temporary fs root references and let the normal merge and cleanup paths handle the relocation roots. Fault injection on a pending-relocation image confirmed the cleanup gap. With an injected first-commit failure, 25 fs roots had reloc_root set with fs_error=0. With this fix, the same failure path drops that count to 0 before mount fails.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of references during btrfs filesystem relocation recovery. When recovery fails, cleanup processes do not properly drop references to relocation roots, leaving temporary references active. This can lead to memory leaks or resource exhaustion during filesystem operations.

Detection Guidance

This vulnerability is specific to the Linux kernel's btrfs filesystem and requires kernel-level inspection. Detection involves checking for uncleared relocation root references during btrfs recovery. Use commands like 'dmesg | grep btrfs' to check for btrfs-related errors, or inspect kernel logs for recovery failures. No direct network detection commands are applicable.

Impact Analysis

This vulnerability may cause filesystem instability or crashes during btrfs recovery operations. It could lead to resource leaks, degraded performance, or unexpected system behavior if recovery fails due to errors like out-of-memory conditions.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or other common standards and regulations. It is a Linux kernel issue related to filesystem recovery that could lead to resource leaks but does not involve data breaches or unauthorized access.

Mitigation Strategies

Update the Linux kernel to the latest patched version to resolve the btrfs relocation recovery issue. Monitor system logs for btrfs-related errors during mount or recovery operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89645. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart