CVE-2026-98082
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix the possible bioc_list memory leak during error
There are two possible ways to leak bioc memory on btrfs_ordered_extent::bioc_list:
An error occurred for btrfs_insert_one_raid_extent() Then the function btrfs_insert_raid_extent() immediately return without freeing any bioc in the bioc_list.
An ordered extent hit an IO error In that case the ordered extent will have BTRFS_ORDERED_IOERR set, and skip the call on btrfs_insert_raid_extent() completely.
Fix the problem by:
Introduce a new helper, btrfs_cleanup_ordered_bioc_list() Which will remove all bioc from the bioc_list, and release the bioc.
Call the above helper for btrfs_insert_raid_extent() So that the cleanup helper is always called no matter what.
Call the above helper for btrfs_finish_one_ordered() This is called just before the final release on the ordered extent.
This was reported by Sashiko when reviewing another patch.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 02c372e1f016e5113217597ab37b399c4e407477 < 83f0c973cffb184d019390ffdb5d31de5c85bc61 | affected |
| Linux | Linux | 02c372e1f016e5113217597ab37b399c4e407477 < 1b4d4e890c2c85d0f6365b5a08c48b4bbf85deb0 | affected |
| Linux | Linux | 02c372e1f016e5113217597ab37b399c4e407477 < bb4da45766d16503821f167054db76b735d89e94 | affected |
| Linux | Linux | 02c372e1f016e5113217597ab37b399c4e407477 < afbe73778338e6d1ac8c4486fbdf33f0cc1f2624 | affected |
| Linux | Linux | ab69bf6f8970c09d3735c25094e9471d54365282 | affected |
| Linux | Linux | 6.6.130 < 6.7 | affected |
| Linux | Linux | 6.7 | affected |
| Linux | Linux | 0 < 6.7 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/83f0c973cffb184d019390ffdb5d31de5c85bc61
- https://git.kernel.org/stable/c/1b4d4e890c2c85d0f6365b5a08c48b4bbf85deb0
- https://git.kernel.org/stable/c/bb4da45766d16503821f167054db76b735d89e94
- https://git.kernel.org/stable/c/afbe73778338e6d1ac8c4486fbdf33f0cc1f2624
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.