Action not permitted
Modal body text goes here.
Modal Title
Modal Body
EUVD-2026-375908
European Vulnerability Database identifier assigned by ENISAReserved
2026-10-02 08:40
Assigner
ENISA
Alias of
a CVE record, shown under related vulnerabilities.
This identifier carries no description, severity or references of its own:
they belong to that CVE.
{
"assigner": "ENISA",
"date_reserved": "2026-10-02T08:40:00.395630+00:00",
"id": "EUVD-2026-375908"
}
CVE-2026-93800 (GCVE-0-2026-93800)
Vulnerability from cvelistv5 – Published: 2026-09-24 16:02 – Updated: 2026-10-03 10:57
VLAI
EPSS
VEX
Title
btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()
If during relocation we fail in insert_dirty_subvol() because
btrfs_update_reloc_root() returned an error, we will leave a root's
reloc_root field pointing to a reloc root that was freed instead of NULL,
resulting later in a use-after-free, or double free attempt during
unmount.
The sequence of steps is this:
1) During relocation the call to btrfs_update_reloc_root() in
insert_dirty_subvol() fails, so insert_dirty_subvol() returns the
error to merge_reloc_root() without adding the root to the list
rc->dirty_subvol_roots;
2) Then merge_reloc_root() aborts the current transaction because
insert_dirty_subvol() returned an error;
3) Up the call chain, merge_reloc_roots() gets the error, adds the
reloc root for root X to the local reloc_roots list and jumps to the
'out' label, where it calls free_reloc_roots() to free all the reloc
roots in the local reloc_roots list. This frees the reloc root for
root X;
4) We go up the call chain to relocate_block_group() which calls
clean_dirty_subvols() to go over dirty roots and set their
->reloc_root field to NULL, but root X is not in the dirty_subvol_roots
list, so its ->reloc_root still points to a reloc root;
5) Relocation finishes, with an error and a transaction abort, but the
->reloc_root field for root X still points to the reloc root that was
freed in step 3;
6) When unmounting the fs we end up calling:
btrfs_free_fs_roots()
btrfs_drop_and_free_fs_root()
--> calls btrfs_put_root() against root X's ->reloc_root
which is not NULL and points to the already freed
reloc root in step 4 above
Resulting in a use-after-free to a double free attempt.
Syzbot reported this with the following dmesg/syslog:
[ 106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)
[ 106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure
[ 106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5
[ 106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.
[ 106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0
[ 106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure
[ 106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly
[ 106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure
[ 106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1
[ 106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30
[ 106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30
[ 106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409
[ 106.682946][ T5338] ==================================================================
[ 106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250
[ 106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338
[ 106.693173][ T5338]
[ 106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)
[ 106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
[ 106.694300][ T5338] Call Trace:
[ 106.694308][ T5338] <TASK>
[ 106.694314][ T5338] dump_stack_lvl+0xe8/0x150
[ 106.694331][ T5338] print_address_description+0x55/0x1e0
[ 106.694343][ T5338] ? btrfs_put_root+0x2f/0x250
[ 106.694358][ T5338] print_report+0x58/0x70
[ 106.
---truncated---
Severity
No CVSS data available.
Assigner
References
7 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
f32b84d7c977e1906a4781b93b3c93090b6cd675 , < 5a247097c5f94b51ffc991b444d998ad6e85875f
(git)
Affected: 592fbcd50c99b8adf999a2a54f9245caff333139 , < 6372dd394ea907cd85a7a8063db320ec73dfaed0 (git) Affected: 592fbcd50c99b8adf999a2a54f9245caff333139 , < 9f599d120b2b79d2d937c3935b7cdf2697514283 (git) Affected: 592fbcd50c99b8adf999a2a54f9245caff333139 , < a01837ae174a2a968c245a30e6dd010f50eaf05d (git) Affected: 592fbcd50c99b8adf999a2a54f9245caff333139 , < 97a540d72ebcb21853d11f2a56782fe377f358e7 (git) Affected: 592fbcd50c99b8adf999a2a54f9245caff333139 , < fda1b6636ff1846f00643e791099db5564b547d9 (git) Affected: 592fbcd50c99b8adf999a2a54f9245caff333139 , < 83201804efa4a5168be754e1dfc9b2faee760cac (git) Affected: aa18bc1ff8a51f082d5b3b6d07693797637b4028 (git) Affected: 4cb0aea2e250eee35ccfac5f5395cd8f3238a9e5 (git) Affected: 5.10.36 , < 5.10.271 (semver) Affected: 5.11.20 , < 5.12 (semver) Affected: 5.12.3 , < 5.13 (semver) |
|
| Linux | Linux |
Affected:
5.13
Unaffected: 0 , < 5.13 (semver) Unaffected: 5.10.271 , ≤ 5.10.* (semver) Unaffected: 5.15.222 , ≤ 5.15.* (semver) Unaffected: 6.1.189 , ≤ 6.1.* (semver) Unaffected: 6.6.158 , ≤ 6.6.* (semver) Unaffected: 6.12.111 , ≤ 6.12.* (semver) Unaffected: 6.18.53 , ≤ 6.18.* (semver) Unaffected: 7.2 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5a247097c5f94b51ffc991b444d998ad6e85875f",
"status": "affected",
"version": "f32b84d7c977e1906a4781b93b3c93090b6cd675",
"versionType": "git"
},
{
"lessThan": "6372dd394ea907cd85a7a8063db320ec73dfaed0",
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"versionType": "git"
},
{
"lessThan": "9f599d120b2b79d2d937c3935b7cdf2697514283",
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"versionType": "git"
},
{
"lessThan": "a01837ae174a2a968c245a30e6dd010f50eaf05d",
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"versionType": "git"
},
{
"lessThan": "97a540d72ebcb21853d11f2a56782fe377f358e7",
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"versionType": "git"
},
{
"lessThan": "fda1b6636ff1846f00643e791099db5564b547d9",
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"versionType": "git"
},
{
"lessThan": "83201804efa4a5168be754e1dfc9b2faee760cac",
"status": "affected",
"version": "592fbcd50c99b8adf999a2a54f9245caff333139",
"versionType": "git"
},
{
"status": "affected",
"version": "aa18bc1ff8a51f082d5b3b6d07693797637b4028",
"versionType": "git"
},
{
"status": "affected",
"version": "4cb0aea2e250eee35ccfac5f5395cd8f3238a9e5",
"versionType": "git"
},
{
"lessThan": "5.10.271",
"status": "affected",
"version": "5.10.36",
"versionType": "semver"
},
{
"lessThan": "5.12",
"status": "affected",
"version": "5.11.20",
"versionType": "semver"
},
{
"lessThan": "5.13",
"status": "affected",
"version": "5.12.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"fs/btrfs/relocation.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"lessThan": "5.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.271",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.222",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.271",
"versionStartIncluding": "5.10.36",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.222",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.189",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.158",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.111",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.53",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.11.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.12.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()\n\nIf during relocation we fail in insert_dirty_subvol() because\nbtrfs_update_reloc_root() returned an error, we will leave a root\u0027s\nreloc_root field pointing to a reloc root that was freed instead of NULL,\nresulting later in a use-after-free, or double free attempt during\nunmount.\n\nThe sequence of steps is this:\n\n1) During relocation the call to btrfs_update_reloc_root() in\n insert_dirty_subvol() fails, so insert_dirty_subvol() returns the\n error to merge_reloc_root() without adding the root to the list\n rc-\u003edirty_subvol_roots;\n\n2) Then merge_reloc_root() aborts the current transaction because\n insert_dirty_subvol() returned an error;\n\n3) Up the call chain, merge_reloc_roots() gets the error, adds the\n reloc root for root X to the local reloc_roots list and jumps to the\n \u0027out\u0027 label, where it calls free_reloc_roots() to free all the reloc\n roots in the local reloc_roots list. This frees the reloc root for\n root X;\n\n4) We go up the call chain to relocate_block_group() which calls\n clean_dirty_subvols() to go over dirty roots and set their\n -\u003ereloc_root field to NULL, but root X is not in the dirty_subvol_roots\n list, so its -\u003ereloc_root still points to a reloc root;\n\n5) Relocation finishes, with an error and a transaction abort, but the\n -\u003ereloc_root field for root X still points to the reloc root that was\n freed in step 3;\n\n6) When unmounting the fs we end up calling:\n\n btrfs_free_fs_roots()\n btrfs_drop_and_free_fs_root()\n --\u003e calls btrfs_put_root() against root X\u0027s -\u003ereloc_root\n which is not NULL and points to the already freed\n reloc root in step 4 above\n\n Resulting in a use-after-free to a double free attempt.\n\nSyzbot reported this with the following dmesg/syslog:\n\n [ 106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)\n [ 106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure\n [ 106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5\n [ 106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.\n [ 106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0\n [ 106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure\n [ 106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly\n [ 106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure\n [ 106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1\n [ 106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30\n [ 106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30\n [ 106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409\n [ 106.682946][ T5338] ==================================================================\n [ 106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250\n [ 106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338\n [ 106.693173][ T5338]\n [ 106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)\n [ 106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n [ 106.694300][ T5338] Call Trace:\n [ 106.694308][ T5338] \u003cTASK\u003e\n [ 106.694314][ T5338] dump_stack_lvl+0xe8/0x150\n [ 106.694331][ T5338] print_address_description+0x55/0x1e0\n [ 106.694343][ T5338] ? btrfs_put_root+0x2f/0x250\n [ 106.694358][ T5338] print_report+0x58/0x70\n [ 106.\n---truncated---"
}
],
"providerMetadata": {
"dateUpdated": "2026-10-03T10:57:34.733Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5a247097c5f94b51ffc991b444d998ad6e85875f"
},
{
"url": "https://git.kernel.org/stable/c/6372dd394ea907cd85a7a8063db320ec73dfaed0"
},
{
"url": "https://git.kernel.org/stable/c/9f599d120b2b79d2d937c3935b7cdf2697514283"
},
{
"url": "https://git.kernel.org/stable/c/a01837ae174a2a968c245a30e6dd010f50eaf05d"
},
{
"url": "https://git.kernel.org/stable/c/97a540d72ebcb21853d11f2a56782fe377f358e7"
},
{
"url": "https://git.kernel.org/stable/c/fda1b6636ff1846f00643e791099db5564b547d9"
},
{
"url": "https://git.kernel.org/stable/c/83201804efa4a5168be754e1dfc9b2faee760cac"
}
],
"title": "btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-93800",
"datePublished": "2026-09-24T16:02:34.370Z",
"dateReserved": "2026-09-18T17:59:28.789Z",
"dateUpdated": "2026-10-03T10:57:34.733Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…