{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-93800","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-18T17:59:28.789Z","datePublished":"2026-09-24T16:02:34.370Z","dateUpdated":"2026-10-03T10:57:34.733Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-10-03T10:57:34.733Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()\n\nIf during relocation we fail in insert_dirty_subvol() because\nbtrfs_update_reloc_root() returned an error, we will leave a root's\nreloc_root field pointing to a reloc root that was freed instead of NULL,\nresulting later in a use-after-free, or double free attempt during\nunmount.\n\nThe sequence of steps is this:\n\n1) During relocation the call to btrfs_update_reloc_root() in\n   insert_dirty_subvol() fails, so insert_dirty_subvol() returns the\n   error to merge_reloc_root() without adding the root to the list\n   rc->dirty_subvol_roots;\n\n2) Then merge_reloc_root() aborts the current transaction because\n   insert_dirty_subvol() returned an error;\n\n3) Up the call chain, merge_reloc_roots() gets the error, adds the\n   reloc root for root X to the local reloc_roots list and jumps to the\n   'out' label, where it calls free_reloc_roots() to free all the reloc\n   roots in the local reloc_roots list. This frees the reloc root for\n   root X;\n\n4) We go up the call chain to relocate_block_group() which calls\n   clean_dirty_subvols() to go over dirty roots and set their\n   ->reloc_root field to NULL, but root X is not in the dirty_subvol_roots\n   list, so its ->reloc_root still points to a reloc root;\n\n5) Relocation finishes, with an error and a transaction abort, but the\n   ->reloc_root field for root X still points to the reloc root that was\n   freed in step 3;\n\n6) When unmounting the fs we end up calling:\n\n     btrfs_free_fs_roots()\n        btrfs_drop_and_free_fs_root()\n           --> calls btrfs_put_root() against root X's ->reloc_root\n               which is not NULL and points to the already freed\n               reloc root in step 4 above\n\n  Resulting in a use-after-free to a double free attempt.\n\nSyzbot reported this with the following dmesg/syslog:\n\n   [  106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)\n   [  106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure\n   [  106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5\n   [  106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.\n   [  106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0\n   [  106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure\n   [  106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly\n   [  106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure\n   [  106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1\n   [  106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30\n   [  106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30\n   [  106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409\n   [  106.682946][ T5338] ==================================================================\n   [  106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250\n   [  106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338\n   [  106.693173][ T5338]\n   [  106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)\n   [  106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n   [  106.694300][ T5338] Call Trace:\n   [  106.694308][ T5338]  <TASK>\n   [  106.694314][ T5338]  dump_stack_lvl+0xe8/0x150\n   [  106.694331][ T5338]  print_address_description+0x55/0x1e0\n   [  106.694343][ T5338]  ? btrfs_put_root+0x2f/0x250\n   [  106.694358][ T5338]  print_report+0x58/0x70\n   [  106.\n---truncated---"}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/relocation.c"],"versions":[{"version":"f32b84d7c977e1906a4781b93b3c93090b6cd675","lessThan":"5a247097c5f94b51ffc991b444d998ad6e85875f","status":"affected","versionType":"git"},{"version":"592fbcd50c99b8adf999a2a54f9245caff333139","lessThan":"6372dd394ea907cd85a7a8063db320ec73dfaed0","status":"affected","versionType":"git"},{"version":"592fbcd50c99b8adf999a2a54f9245caff333139","lessThan":"9f599d120b2b79d2d937c3935b7cdf2697514283","status":"affected","versionType":"git"},{"version":"592fbcd50c99b8adf999a2a54f9245caff333139","lessThan":"a01837ae174a2a968c245a30e6dd010f50eaf05d","status":"affected","versionType":"git"},{"version":"592fbcd50c99b8adf999a2a54f9245caff333139","lessThan":"97a540d72ebcb21853d11f2a56782fe377f358e7","status":"affected","versionType":"git"},{"version":"592fbcd50c99b8adf999a2a54f9245caff333139","lessThan":"fda1b6636ff1846f00643e791099db5564b547d9","status":"affected","versionType":"git"},{"version":"592fbcd50c99b8adf999a2a54f9245caff333139","lessThan":"83201804efa4a5168be754e1dfc9b2faee760cac","status":"affected","versionType":"git"},{"version":"aa18bc1ff8a51f082d5b3b6d07693797637b4028","status":"affected","versionType":"git"},{"version":"4cb0aea2e250eee35ccfac5f5395cd8f3238a9e5","status":"affected","versionType":"git"},{"version":"5.10.36","lessThan":"5.10.271","status":"affected","versionType":"semver"},{"version":"5.11.20","lessThan":"5.12","status":"affected","versionType":"semver"},{"version":"5.12.3","lessThan":"5.13","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["fs/btrfs/relocation.c"],"versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","status":"unaffected","versionType":"semver"},{"version":"5.10.271","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.222","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.189","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.158","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.111","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.53","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.36","versionEndExcluding":"5.10.271"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"5.15.222"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"6.1.189"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"6.6.158"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"6.12.111"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"6.18.53"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.13","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11.20"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/5a247097c5f94b51ffc991b444d998ad6e85875f"},{"url":"https://git.kernel.org/stable/c/6372dd394ea907cd85a7a8063db320ec73dfaed0"},{"url":"https://git.kernel.org/stable/c/9f599d120b2b79d2d937c3935b7cdf2697514283"},{"url":"https://git.kernel.org/stable/c/a01837ae174a2a968c245a30e6dd010f50eaf05d"},{"url":"https://git.kernel.org/stable/c/97a540d72ebcb21853d11f2a56782fe377f358e7"},{"url":"https://git.kernel.org/stable/c/fda1b6636ff1846f00643e791099db5564b547d9"},{"url":"https://git.kernel.org/stable/c/83201804efa4a5168be754e1dfc9b2faee760cac"}],"title":"btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()","x_generator":{"engine":"bippy-1.2.0"}}}}