PT-2026-98754 · Linux · Linux

CVE-2026-98091

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
btrfs: detach failed sprout device from transaction update list
When creating the first metadata chunk for a sprout filesystem, create chunk() adds the new device to the transaction dev update list through device->post commit list.
If the subsequent system chunk creation fails, btrfs init new device() aborts the transaction and releases the device while post commit list is still linked. This triggers a warning in btrfs free device() and leaves the transaction list referencing freed memory.
Detach the device while holding chunk mutex before releasing it.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98091

Affected Products

Linux