CVE-2026-98279
Received Received - Intake

Btrfs Filesystem Read-Only Due to Verity Cleanup Failure

Vulnerability report for CVE-2026-98279, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: handle lack of space when cleaning up verity items When enable_verity() hits the qgroup limit, rollback_verity() needs its own metadata reservation. When the qgroup limit or lack of space refuses the rollback, the whole filesystem is forced read-only even though the qgroup limit was for one subvolume only. Also orphan cleanup at the next mount fails the same way, so the leftover items are never removed: with -EDQUOT the subvolume stays unreachable, and with -ENOSPC on a full filesystem the next read-write mount fails. Start transactions with btrfs_start_transaction_fallback_global_rsv() in btrfs_orphan_cleanup(), drop_verity_items() and rollback_verity(). Those calls only delete items and free the space in the end, so they may use the global reserve and skip the qgroup limit, which avoids -ENOSPC and -EDQUOT.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
Linux Linux 146054090b0859b28fc39015c7704ccc3c3a347f
Linux Linux 146054090b0859b28fc39015c7704ccc3c3a347f
Linux Linux 146054090b0859b28fc39015c7704ccc3c3a347f
Linux Linux 5.15

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel's btrfs filesystem occurs when handling space limitations during verity item cleanup. If the system runs out of space or hits a quota limit during cleanup, the entire filesystem is forced into a read-only state, even if only one subvolume was affected. This leaves orphaned items that cannot be removed, causing the subvolume to become inaccessible or preventing future read-write mounts.

Detection Guidance

This vulnerability is specific to the Linux kernel's btrfs filesystem and may not have direct network detection methods. Check kernel logs for btrfs-related errors or filesystem read-only transitions. Commands like dmesg | grep btrfs or journalctl -k | grep btrfs may help identify issues.

Impact Analysis

If exploited, this flaw could cause your Linux system to become unresponsive or crash due to filesystem errors. You might lose access to critical data or face repeated system failures during startup if the filesystem enters a read-only state. Recovery may require manual intervention or filesystem repairs.

Mitigation Strategies

Apply the latest Linux kernel updates to patch this vulnerability. Monitor btrfs filesystem space usage and qgroup limits to prevent -ENOSPC or -EDQUOT errors. Ensure regular backups of critical data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98279. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart