CVE-2026-98269
Received
Received - Intake
Btrfs Transaction Abort on Inode Update Failure
Vulnerability report for CVE-2026-98269, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
btrfs: abort transaction on failure to update inode for hole punching and reflinking
If we fail to update the inode we error out without aborting the
transaction, which can result in a persistent inconsistency if after
the failure the transaction is committed, as we have dropped file
extent items from a range and either punched a hole or insert a new file
extent item for that range (for reflinks).
So add the missing transaction abort.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 2aaa66558172b017f36bf38ae69372813dedee9d |
| Linux | Linux | 2aaa66558172b017f36bf38ae69372813dedee9d |
| Linux | Linux | 2aaa66558172b017f36bf38ae69372813dedee9d |
| Linux | Linux | 2aaa66558172b017f36bf38ae69372813dedee9d |
| Linux | Linux | 2aaa66558172b017f36bf38ae69372813dedee9d |
| Linux | Linux | 3.7 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |