{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93798","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.789Z","datePublished":"2026-09-24T16:02:31.291Z","dateUpdated":"2026-10-03T10:57:32.550Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:32.550Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix reloc root cleanup in merge_reloc_roots()\n\nIf the root we got has zero root refs in its root item, we are resetting\nthe root's ->reloc_root without using barriers like we do everywhere else.\nSashiko complained about this while reviewing another patch, and it's\ncorrect (see the Link tag below).\n\nAlso, we should not clear BTRFS_ROOT_DEAD_RELOC_TREE from the root unless\nthe root points to the reloc root we have.\n\nFix this by using clear_reloc_root(), which issues the memory barrier\nafter setting the root's ->reloc_root to NULL and before clearing the bit\nBTRFS_ROOT_DEAD_RELOC_TREE from the root."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - merge_reloc_roots() is reached from local VFS activity: unlink/write call btrfs_update_block_group() which btrfs_mark_bg_to_reclaim(); btrfs_reclaim_bgs_work() then runs btrfs_relocate_chunk()->btrfs_relocate_block_group()->relocate_block_group()->prepare_to_merge()->merge_reloc_roots(). No network protocol supplies the causing state.\nAC:L - When relocate_block_group() fails (the attacker can force ENOSPC via extra allocations), prepare_to_merge() leaves reloc roots at 0 refs and merge_reloc_roots() NULLs root->reloc_root then clear_bit(BTRFS_ROOT_DEAD_RELOC_TREE) without smp_wmb(). Concurrent writes invoke btrfs_init_reloc_root()/have_reloc_root() on that same root, so the attacker drives both sides.\nPR:L - BTRFS_IOC_BALANCE requires capable(CAP_SYS_ADMIN), but btrfs_buffered_write() and unlink used to mark a block group reclaimable have no capability gate. btrfs_fs_type lacks FS_USERNS_MOUNT, so the volume is admin-mounted, yet any unprivileged uid with write permission on that mount can induce reclaim into merge_reloc_roots().\nUI:N - The attacker induces the 0-ref merge_reloc_roots() cleanup with their own writes and deletions on a btrfs they can already write, then races have_reloc_root() with further writes or btrfs_ioctl_snap_create(); no second user needs to mount an image or run balance.\nS:U - The use-after-free is of the struct btrfs_root stored in fs_root->reloc_root inside the same host kernel that mounted the volume; merge_reloc_roots() does not cross a VM, IOMMU, or sandbox authority.\nC:H - Missing smp_wmb() in merge_reloc_roots() lets have_reloc_root() see BTRFS_ROOT_DEAD_RELOC_TREE already clear while still loading the old root->reloc_root pointer; btrfs_should_ignore_reloc_root() then reads reloc_root->commit_root after the matching btrfs_put_root() dropped that reloc root.\nI:H - The same stale reloc_root is written by btrfs_init_reloc_root() via btrfs_set_root_last_trans() and by commit_fs_roots()->btrfs_update_reloc_root() which mutates reloc_root->root_item, giving a write-after-free of struct btrfs_root.\nA:H - Using the dangling reloc_root after merge_reloc_roots()'s btrfs_put_root() oopses; if clear_bit(BTRFS_ROOT_DEAD_RELOC_TREE) becomes visible while the pointer still refers to the 0-ref tree, btrfs_reloc_pre_snapshot() hits BUG_ON(btrfs_root_refs(&root->root_item)==0)."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/relocation.c"],"versions":[{"version":"1dae7e0e58b484eaa43d530f211098fdeeb0f404","lessThan":"29531470b1bf1e8bd2df4941fe913106edbca615","status":"affected","versionType":"git"},{"version":"1dae7e0e58b484eaa43d530f211098fdeeb0f404","lessThan":"415f8665a969d3c906e4fd7c90fcbb4b357886f6","status":"affected","versionType":"git"},{"version":"1dae7e0e58b484eaa43d530f211098fdeeb0f404","lessThan":"ee695a968aa73b1e67ccbf2133dc0e54381d32b2","status":"affected","versionType":"git"},{"version":"1dae7e0e58b484eaa43d530f211098fdeeb0f404","lessThan":"0bc25f0a2d1b3e0a691431c4d7aef36afcd527c5","status":"affected","versionType":"git"},{"version":"1dae7e0e58b484eaa43d530f211098fdeeb0f404","lessThan":"ab48583aa9948205ff9a6470e23dbff74c565e24","status":"affected","versionType":"git"},{"version":"1dae7e0e58b484eaa43d530f211098fdeeb0f404","lessThan":"63d6b1f04cd91c825329712aa526215ffa5d11ca","status":"affected","versionType":"git"},{"version":"1dae7e0e58b484eaa43d530f211098fdeeb0f404","lessThan":"b78fe9563e2d5ae47805f1e5dc722c91fd30e1f8","status":"affected","versionType":"git"},{"version":"ee08663380ffd5a45a1c87580fbc305e8413c235","status":"affected","versionType":"git"},{"version":"33823378ff2b510fd7b566f25bb18438aeb9b23b","status":"affected","versionType":"git"},{"version":"5.4.54","lessThan":"5.5","status":"affected","versionType":"semver"},{"version":"5.7.11","lessThan":"5.8","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/relocation.c"],"versions":[{"version":"5.8","status":"affected"},{"version":"0","lessThan":"5.8","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.8","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.54"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.7.11"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/29531470b1bf1e8bd2df4941fe913106edbca615"},{"url":"https://git.kernel.org/stable/c/415f8665a969d3c906e4fd7c90fcbb4b357886f6"},{"url":"https://git.kernel.org/stable/c/ee695a968aa73b1e67ccbf2133dc0e54381d32b2"},{"url":"https://git.kernel.org/stable/c/0bc25f0a2d1b3e0a691431c4d7aef36afcd527c5"},{"url":"https://git.kernel.org/stable/c/ab48583aa9948205ff9a6470e23dbff74c565e24"},{"url":"https://git.kernel.org/stable/c/63d6b1f04cd91c825329712aa526215ffa5d11ca"},{"url":"https://git.kernel.org/stable/c/b78fe9563e2d5ae47805f1e5dc722c91fd30e1f8"}],"title":"btrfs: fix reloc root cleanup in merge_reloc_roots()","x_generator":{"engine":"bippy-1.2.0"}}}}