Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98090— btrfs: restore active device pointers after failed sprout

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: btrfs:在失败的 sprout 操作后恢复活动设备指针 函数在创建第一个可写块之前,会将 以及可能的 从种子(seed)设备切换至新的 sprout 设备。 如果块创建或随后的 sprout 设置失败,错误处理路径会释放新设备,但未将这些指针恢复至原状态。此时, 可能会解引用已释放的 ,从而导致系统崩溃。 本修复确保在移除并释放失败的 sprout 设备之前,先将活动设备指针恢复至最新的种子设备。

AI Predicted 7.8 Difficulty: Moderate EPSS 0.17% · P6

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 17

VendorProduct Version RangeStatus
Linux Linux a6e7e218a4d6488d56727a7d9aee1b7e78c0c485< 46863a9f93186e620c70584f91c8d5d95da83eff affected
b7cb29e666fe79dda5dbe5f57fb7c92413bf161c< 49179f13c04735c55fd0f43b03696c015b067137 affected
b7cb29e666fe79dda5dbe5f57fb7c92413bf161c< 0a0ee38ad6324ac1603079bb785f784191576bd5 affected
b7cb29e666fe79dda5dbe5f57fb7c92413bf161c< 2ee5c4bc11007c51f63f0c1be5d3f07f2b404ff7 affected
b7cb29e666fe79dda5dbe5f57fb7c92413bf161c< e127ac29a52134d0f4cba39d38e4b375deb3d1aa affected
b7cb29e666fe79dda5dbe5f57fb7c92413bf161c< b79b4b29003690acfade8241998fc0104ef9c84c affected
b7cb29e666fe79dda5dbe5f57fb7c92413bf161c< e0b54613aabeb8e9da597f23b90c6a03d0981986 affected
5.15.11< 5.15.222 affected
… +9 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98090

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
btrfs: restore active device pointers after failed sprout
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: btrfs: restore active device pointers after failed sprout btrfs_init_new_device() switches latest_dev and possibly s_bdev from the seed device to the new sprout device before creating the first writable chunks. If chunk creation or the subsequent sprout setup fails, the error path releases the new device without switching those pointers back. btrfs_show_devname() can then dereference the freed latest_dev and crash. Restore the active device pointers to the latest seed device before removing and releasing the failed sprout device.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux a6e7e218a4d6488d56727a7d9aee1b7e78c0c485 ~ 46863a9f93186e620c70584f91c8d5d95da83eff -
Linux Linux 5.16 -

II. Public POCs for CVE-2026-98090

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98090

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98090 (7)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98002 7.8 HIGH iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-97575 7.8 HIGH media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-97576 7.8 HIGH media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-97941 7.8 HIGH mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-97937 7.8 HIGH ftrace: fork: Initialize function graph state before copy_exec_state()
CVE-2026-97580 7.8 HIGH media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98090

No comments yet


Leave a comment