CVE-2026-98245
Received
Received - Intake
Btrfs Use-After-Free in mark_block_group_to_copy
Vulnerability report for CVE-2026-98245, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
mark_block_group_to_copy() iterates over the commit root with
skip_locking=true. A concurrent transaction commit can swap and free
the commit root during iteration, causing use-after-free when
accessing extent buffers.
Fix it by using path->need_commit_sem to protect the commit root search.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 78ce9fc269af6e69c1399ab910ba6bc81c934f67 |
| Linux | Linux | 78ce9fc269af6e69c1399ab910ba6bc81c934f67 |
| Linux | Linux | 78ce9fc269af6e69c1399ab910ba6bc81c934f67 |
| Linux | Linux | 78ce9fc269af6e69c1399ab910ba6bc81c934f67 |
| Linux | Linux | 5.12 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |