btrfs: restore active device pointers after failed sprout

Summary

CVECVE-2026-98090
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-25 11:17:38 UTC
Updated2026-09-30 14:10:59 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: btrfs: restore active device pointers after failed sprout btrfs_init_new_device() switches latest_dev and possibly s_bdev from the seed device to the new sprout device before creating the first writable chunks. If chunk creation or the subsequent sprout setup fails, the error path releases the new device without switching those pointers back. btrfs_show_devname() can then dereference the freed latest_dev and crash. Restore the active device pointers to the latest seed device before removing and releasing the failed sprout device.

Risk And Classification

EPSS: 0.001680000 probability, percentile 0.054000000 (date 2026-09-27)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected b7cb29e666fe79dda5dbe5f57fb7c92413bf161c 2ee5c4bc11007c51f63f0c1be5d3f07f2b404ff7 git Not specified
CNA Linux Linux affected b7cb29e666fe79dda5dbe5f57fb7c92413bf161c e127ac29a52134d0f4cba39d38e4b375deb3d1aa git Not specified
CNA Linux Linux affected b7cb29e666fe79dda5dbe5f57fb7c92413bf161c b79b4b29003690acfade8241998fc0104ef9c84c git Not specified
CNA Linux Linux affected b7cb29e666fe79dda5dbe5f57fb7c92413bf161c e0b54613aabeb8e9da597f23b90c6a03d0981986 git Not specified
CNA Linux Linux affected a6e7e218a4d6488d56727a7d9aee1b7e78c0c485 git Not specified
CNA Linux Linux affected 5.15.11 5.16 semver Not specified
CNA Linux Linux affected 5.16 Not specified
CNA Linux Linux unaffected 5.16 semver Not specified
CNA Linux Linux unaffected 6.12.111 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.53 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.7 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc2 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/e127ac29a52134d0f4cba39d38e4b375deb3d1aa 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2ee5c4bc11007c51f63f0c1be5d3f07f2b404ff7 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e0b54613aabeb8e9da597f23b90c6a03d0981986 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b79b4b29003690acfade8241998fc0104ef9c84c 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report