Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98091— btrfs: detach failed sprout device from transaction update list

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已解决以下漏洞: btrfs:将失败的 sprout 设备从事务更新列表中分离 在为 sprout 文件系统创建第一个元数据块(chunk)时,create_chunk() 函数会通过 device->post_commit_list 将新设备添加到当前事务的 dev_update_list 中。 如果随后系统块(system chunk)的创建失败,btrfs_init_new_device() 函数会中止事务并释放该设备,但此时该设备仍链接在 post_commit_list 中。这会导

AI Predicted 6.5 Difficulty: Theoretical EPSS 0.18% · P7

Possible ATT&CK Techniques 1 AI

T1211 · Exploitation for Stealth

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux bbbf7243d62d8be73b7ef60721c127b36b2d523e< 2a57fb1d5ce8f316b81bbb60e6df245ebc816ffc affected
bbbf7243d62d8be73b7ef60721c127b36b2d523e< 86eff3052054e8f3b059b2d5845b6dcca021f20c affected
bbbf7243d62d8be73b7ef60721c127b36b2d523e< 63bfa52eb3289517aa82cb90e1189385873aae21 affected
bbbf7243d62d8be73b7ef60721c127b36b2d523e< 7fe9dfbca43464baa8f050447a4837587b18adec affected
bbbf7243d62d8be73b7ef60721c127b36b2d523e< e9e7e37afa85db770e6084360b21a21a8b3a583f affected
bbbf7243d62d8be73b7ef60721c127b36b2d523e< 8b001df2b37ca022f710f3254fbb0bcd6d9e1bed affected
bbbf7243d62d8be73b7ef60721c127b36b2d523e< 0ea6814bc0ff7cff443241bd34db9f0f828f3190 affected
bbbf7243d62d8be73b7ef60721c127b36b2d523e< c93b3c43df561cd9f592cee20ae058b563f9e5b6 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98091

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
btrfs: detach failed sprout device from transaction update list
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: btrfs: detach failed sprout device from transaction update list When creating the first metadata chunk for a sprout filesystem, create_chunk() adds the new device to the transaction dev_update_list through device->post_commit_list. If the subsequent system chunk creation fails, btrfs_init_new_device() aborts the transaction and releases the device while post_commit_list is still linked. This triggers a warning in btrfs_free_device() and leaves the transaction list referencing freed memory. Detach the device while holding chunk_mutex before releasing it.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux bbbf7243d62d8be73b7ef60721c127b36b2d523e ~ 2a57fb1d5ce8f316b81bbb60e6df245ebc816ffc -
Linux Linux 5.2 -

II. Public POCs for CVE-2026-98091

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98091

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98091 (7)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98002 7.8 HIGH iommu/amd: Fix ineffective error check in nested domain allocation
CVE-2026-97575 7.8 HIGH media: v4l2-ctrls: validate AV1 tile counts
CVE-2026-97576 7.8 HIGH media: v4l2-ctrls: validate HEVC tile counts
CVE-2026-97941 7.8 HIGH mm/slab: take n->list_lock in __slab_try_return_freelist() to avoid race
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events
CVE-2026-97937 7.8 HIGH ftrace: fork: Initialize function graph state before copy_exec_state()
CVE-2026-97580 7.8 HIGH media: rkvdec: bound HEVC tile loops and PPS id to the array capacity
CVE-2026-97940 7.8 HIGH ipv6: fix fib6 walker UAF on seq stop

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98091

No comments yet


Leave a comment