{"api_version":"1","generated_at":"2026-08-18T05:17:43+00:00","cve":"CVE-2026-68422","urls":{"html":"https://cve.report/CVE-2026-68422","api":"https://cve.report/api/cve/CVE-2026-68422.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-68422","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-68422"},"summary":{"title":"btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()\n\nIf we have an unexpected reloc_root for our root, we jump to the out label\nbut never drop the reference we obtained for root, resulting in a leak.\nAdd a missing btrfs_put_root() call.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-10 13:20:36","updated_at":"2026-08-17 06:17:51"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/7591d1727067d6063247901ad25c4bdc4e5695c4","name":"https://git.kernel.org/stable/c/7591d1727067d6063247901ad25c4bdc4e5695c4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b3d39b03799600c76c33486e2d29b73a771023db","name":"https://git.kernel.org/stable/c/b3d39b03799600c76c33486e2d29b73a771023db","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/60a23d4ea169e27403f3bb023bb98036797c0206","name":"https://git.kernel.org/stable/c/60a23d4ea169e27403f3bb023bb98036797c0206","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ce6050bafb4e33377dc17fcc357736bfc351180c","name":"https://git.kernel.org/stable/c/ce6050bafb4e33377dc17fcc357736bfc351180c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/72f673d1c1deb819554d3e7e154f6d84301eb735","name":"https://git.kernel.org/stable/c/72f673d1c1deb819554d3e7e154f6d84301eb735","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68422","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68422","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 24213fa46c7080c31d79aa2e3e2f0d9480cab700 b3d39b03799600c76c33486e2d29b73a771023db git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 24213fa46c7080c31d79aa2e3e2f0d9480cab700 72f673d1c1deb819554d3e7e154f6d84301eb735 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 24213fa46c7080c31d79aa2e3e2f0d9480cab700 60a23d4ea169e27403f3bb023bb98036797c0206 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 24213fa46c7080c31d79aa2e3e2f0d9480cab700 7591d1727067d6063247901ad25c4bdc4e5695c4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 24213fa46c7080c31d79aa2e3e2f0d9480cab700 ce6050bafb4e33377dc17fcc357736bfc351180c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.13","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.13 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.148 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.101 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.42 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.6 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"68422","cve":"CVE-2026-68422","epss":"0.002090000","percentile":"0.113210000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:47"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"b3d39b03799600c76c33486e2d29b73a771023db","status":"affected","version":"24213fa46c7080c31d79aa2e3e2f0d9480cab700","versionType":"git"},{"lessThan":"72f673d1c1deb819554d3e7e154f6d84301eb735","status":"affected","version":"24213fa46c7080c31d79aa2e3e2f0d9480cab700","versionType":"git"},{"lessThan":"60a23d4ea169e27403f3bb023bb98036797c0206","status":"affected","version":"24213fa46c7080c31d79aa2e3e2f0d9480cab700","versionType":"git"},{"lessThan":"7591d1727067d6063247901ad25c4bdc4e5695c4","status":"affected","version":"24213fa46c7080c31d79aa2e3e2f0d9480cab700","versionType":"git"},{"lessThan":"ce6050bafb4e33377dc17fcc357736bfc351180c","status":"affected","version":"24213fa46c7080c31d79aa2e3e2f0d9480cab700","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.13"},{"lessThan":"5.13","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.148","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.101","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.42","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.148","versionStartIncluding":"5.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.101","versionStartIncluding":"5.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.42","versionStartIncluding":"5.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.6","versionStartIncluding":"5.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.13","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()\n\nIf we have an unexpected reloc_root for our root, we jump to the out label\nbut never drop the reference we obtained for root, resulting in a leak.\nAdd a missing btrfs_put_root() call."}],"providerMetadata":{"dateUpdated":"2026-08-17T05:05:17.652Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/b3d39b03799600c76c33486e2d29b73a771023db"},{"url":"https://git.kernel.org/stable/c/72f673d1c1deb819554d3e7e154f6d84301eb735"},{"url":"https://git.kernel.org/stable/c/60a23d4ea169e27403f3bb023bb98036797c0206"},{"url":"https://git.kernel.org/stable/c/7591d1727067d6063247901ad25c4bdc4e5695c4"},{"url":"https://git.kernel.org/stable/c/ce6050bafb4e33377dc17fcc357736bfc351180c"}],"title":"btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-68422","datePublished":"2026-08-10T12:04:42.949Z","dateReserved":"2026-07-30T09:28:09.392Z","dateUpdated":"2026-08-17T05:05:17.652Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 13:20:36","lastModifiedDate":"2026-08-17 06:17:51","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"68422","Ordinal":"1","Title":"btrfs: fix root leak if its reloc root is unexpected in merge_re","CVE":"CVE-2026-68422","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"68422","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()\n\nIf we have an unexpected reloc_root for our root, we jump to the out label\nbut never drop the reference we obtained for root, resulting in a leak.\nAdd a missing btrfs_put_root() call.","Type":"Description","Title":"btrfs: fix root leak if its reloc root is unexpected in merge_re"}]}}}