PT-2026-98743 · Linux · Linux

CVE-2026-98080

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
btrfs: do not force reloc root creation during qgroup account snapshot()
[BUG] When running btrfs/252 with quota enabled through MKFS OPTIONS="-O quota", it has a high chance to trigger the following kernel warning and flips the fs RO:
BTRFS info (device dm-2): relocating block group 30408704 flags metadata|dup ------------[ cut here ]------------ WARNING: fs/btrfs/extent-tree.c:879 at lookup inline extent backref+0x74b/0x960 [btrfs], CPU#4: btrfs/2173 CPU: 4 UID: 0 PID: 2173 Comm: btrfs Not tainted 7.2.0-rc6-custom+ #457 PREEMPT(full) 3adc6528fb66f7a55fe1095385818e742f200aab Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS unknown 02/02/2022 RIP: 0010:lookup inline extent backref+0x74b/0x960 [btrfs] Call Trace: insert inline extent backref+0x7c/0x160 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] btrfs inc extent ref+0xa9/0x270 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] btrfs run delayed refs+0x4af/0x11c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] btrfs run delayed refs+0x9d/0xf0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] create pending snapshot+0x39d/0xf00 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] create pending snapshots+0x9b/0xc0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] btrfs commit transaction+0x280/0xeb0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] prepare to relocate+0x147/0x200 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] relocate block group+0x6b/0x5e0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] btrfs relocate block group+0x92c/0x2380 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] btrfs relocate chunk+0x3f/0x1a0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] btrfs balance+0xa2c/0x19c0 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] btrfs ioctl+0x2839/0x2d30 [btrfs 32f09462c54d9c922fca74a3e4866f4aa7737b72] x64 sys ioctl+0x416/0x9a0 do syscall 64+0xe1/0x790 entry SYSCALL 64 after hwframe+0x4b/0x53 ---[ end trace 0000000000000000 ]--- BTRFS info (device dm-2): leaf 4593991680 gen 233 total ptrs 175 free space 5953 owner 2 BTRFS info (device dm-2): refs 3 lock owner 2173 current 2173 item 0 key (166772736 METADATA ITEM 1) itemoff 16250 itemsize 33 extent refs 1 gen 222 flags 2 ref#0: tree block backref root 266 [ Skip the tree dump ] item 174 key (263225344 METADATA ITEM 0) itemoff 10328 itemsize 33 extent refs 1 gen 162 flags 258 ref#0: tree block backref root 267 BTRFS error (device dm-2): extent item not found for insert, bytenr 179847168 num bytes 16384 parent 4594335744 root objectid 273 owner 0 offset 0 BTRFS error (device dm-2): failed to run delayed ref for logical 179847168 num bytes 16384 type 182 action 1 ref mod 1: -117
[CAUSE] The above error is showing that there is a tree reference to a metadata extent that is no longer there.
With "ref verify" mount option (requires CONFIG BTRFS DEBUG), there is some extra debug output:
BTRFS error (device dm-2): dumping block entry [180961280 16384], num refs 0, metadata 1, from disk 0 BTRFS error (device dm-2): root entry 256, num refs 18446744073709551615 BTRFS error (device dm-2): root entry 273, num refs 18446744073709551615 BTRFS error (device dm-2): Ref action 3, root 273, ref root 273, parent 0, owner 0, offset 0, num refs 1 btrfs force cow block+0x129/0x7d0 [btrfs] btrfs cow block+0x10a/0x250 [btrfs] btrfs search slot+0x5eb/0xf40 [btrfs] btrfs insert empty items+0x3a/0x70 [btrfs] insert with overflow+0x53/0x130 [btrfs] btrfs insert dir item+0x125/0x290 [btrfs] btrfs add link+0xaa/0x410 [btrfs] btrfs rename+0x5ea/0xcd0 [btrfs] btrfs rename2+0x28/0x60 [btrfs] vfs rename+0x5b2/0xe10 filename renameat2+0x244/0x430 x64 sys rename+0x48/0x70 do syscall 64+0xe1/0x790 entry SYSCALL 64 after hwframe+0x4b/0x53
---truncated---
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98080

Produtos afetados

Linux