CVE-2026-98081
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: zoned: finish active block group cleanup if call_zone_finish() fails
do_zone_finish() clears BLOCK_GROUP_FLAG_ZONE_IS_ACTIVE before finishing the zones. If call_zone_finish() then fails it returned early, leaving the now inactive block group on fs_info->zone_active_bgs, leaking its reference, the BTRFS_FS_NEED_ZONE_FINISH waiters are never woken, and as its alloc_offset equals the zone capacity btrfs_zone_finish_one_bg() keeps selecting it, spinning btrfs_zoned_activate_one_bg().
Fall through to the cleanup on failure too and return the error, but keep the block group read-only as its zones are left inconsistent.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | d70cbdda75da3f258118a558c087157e073229fb < 36b9cdab44848f25879ca625275c92b007f84653 | affected |
| Linux | Linux | d70cbdda75da3f258118a558c087157e073229fb < 40370f02a1ca3760f8925ffcbe76eb4d91ea758d | affected |
| Linux | Linux | d70cbdda75da3f258118a558c087157e073229fb < e1b168a53174b385e3548bfbd079513b22ac240c | affected |
| Linux | Linux | d70cbdda75da3f258118a558c087157e073229fb < a18a6b93a2843b9d103d3456bbd4b3f90282a379 | affected |
| Linux | Linux | 5.19 | affected |
| Linux | Linux | 0 < 5.19 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/36b9cdab44848f25879ca625275c92b007f84653
- https://git.kernel.org/stable/c/40370f02a1ca3760f8925ffcbe76eb4d91ea758d
- https://git.kernel.org/stable/c/e1b168a53174b385e3548bfbd079513b22ac240c
- https://git.kernel.org/stable/c/a18a6b93a2843b9d103d3456bbd4b3f90282a379
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.