PT-2026-98754 · Linux · Linux

CVE-2026-98091

·

Publicado

2026-09-25

·

Atualizado

2026-09-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
btrfs: detach failed sprout device from transaction update list
When creating the first metadata chunk for a sprout filesystem, create chunk() adds the new device to the transaction dev update list through device->post commit list.
If the subsequent system chunk creation fails, btrfs init new device() aborts the transaction and releases the device while post commit list is still linked. This triggers a warning in btrfs free device() and leaves the transaction list referencing freed memory.
Detach the device while holding chunk mutex before releasing it.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98091

Produtos afetados

Linux