{"api_version":"1","generated_at":"2026-09-13T14:11:23+00:00","cve":"CVE-2026-89645","urls":{"html":"https://cve.report/CVE-2026-89645","api":"https://cve.report/api/cve/CVE-2026-89645.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-89645","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-89645"},"summary":{"title":"btrfs: drop recovered reloc root refs on recovery failure","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: drop recovered reloc root refs on recovery failure\n\nDuring relocation recovery, each fs root gets a reference to its relocation\nroot. If loading or adding a later root fails, or if the first transaction\ncommit fails, btrfs_recover_relocation() jumps to out_unset before\nmerge_reloc_roots() and clean_dirty_subvols().\n\nput_reloc_control() drops the list-owned relocation root references, but it\ndoes not clear fs_root->reloc_root or drop the references owned by those\npointers. Mount cleanup only drops them when BTRFS_FS_ERROR is set, so an\nerror such as -ENOMEM while processing a later root can leave references\nbehind.\n\nKeep temporary references to the fs roots associated during recovery. On\nfailure, clear their reloc_root pointers and drop the corresponding\nreferences. Once the first transaction commit succeeds, drop only the\ntemporary fs root references and let the normal merge and cleanup paths\nhandle the relocation roots.\n\nFault injection on a pending-relocation image confirmed the cleanup gap.\nWith an injected first-commit failure, 25 fs roots had reloc_root set with\nfs_error=0. With this fix, the same failure path drops that count to 0\nbefore mount fails.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-11 20:19:50","updated_at":"2026-09-11 20:19:50"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/6d8ba4572922e336f0b59a80751b018e1e135164","name":"https://git.kernel.org/stable/c/6d8ba4572922e336f0b59a80751b018e1e135164","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2256d6dc5b88841a8a8b4fd9a9f04730705fb6fd","name":"https://git.kernel.org/stable/c/2256d6dc5b88841a8a8b4fd9a9f04730705fb6fd","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/8a64baeb5bbb706b83d2235c1e39f5b77183817f","name":"https://git.kernel.org/stable/c/8a64baeb5bbb706b83d2235c1e39f5b77183817f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/4d43107e807bcd92621106b07f5011411c6341a8","name":"https://git.kernel.org/stable/c/4d43107e807bcd92621106b07f5011411c6341a8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89645","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89645","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f44deb7442edf42abee6be25fca7e3e86061b4c9 2256d6dc5b88841a8a8b4fd9a9f04730705fb6fd git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f44deb7442edf42abee6be25fca7e3e86061b4c9 8a64baeb5bbb706b83d2235c1e39f5b77183817f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f44deb7442edf42abee6be25fca7e3e86061b4c9 4d43107e807bcd92621106b07f5011411c6341a8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f44deb7442edf42abee6be25fca7e3e86061b4c9 6d8ba4572922e336f0b59a80751b018e1e135164 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.7","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.7 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.109 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.50 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.4 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"89645","cve":"CVE-2026-89645","epss":"0.002250000","percentile":"0.131770000","score_date":"2026-09-12","updated_at":"2026-09-13 00:08:17"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"2256d6dc5b88841a8a8b4fd9a9f04730705fb6fd","status":"affected","version":"f44deb7442edf42abee6be25fca7e3e86061b4c9","versionType":"git"},{"lessThan":"8a64baeb5bbb706b83d2235c1e39f5b77183817f","status":"affected","version":"f44deb7442edf42abee6be25fca7e3e86061b4c9","versionType":"git"},{"lessThan":"4d43107e807bcd92621106b07f5011411c6341a8","status":"affected","version":"f44deb7442edf42abee6be25fca7e3e86061b4c9","versionType":"git"},{"lessThan":"6d8ba4572922e336f0b59a80751b018e1e135164","status":"affected","version":"f44deb7442edf42abee6be25fca7e3e86061b4c9","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.7"},{"lessThan":"5.7","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.109","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.50","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.109","versionStartIncluding":"5.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.50","versionStartIncluding":"5.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.4","versionStartIncluding":"5.7","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"5.7","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: drop recovered reloc root refs on recovery failure\n\nDuring relocation recovery, each fs root gets a reference to its relocation\nroot. If loading or adding a later root fails, or if the first transaction\ncommit fails, btrfs_recover_relocation() jumps to out_unset before\nmerge_reloc_roots() and clean_dirty_subvols().\n\nput_reloc_control() drops the list-owned relocation root references, but it\ndoes not clear fs_root->reloc_root or drop the references owned by those\npointers. Mount cleanup only drops them when BTRFS_FS_ERROR is set, so an\nerror such as -ENOMEM while processing a later root can leave references\nbehind.\n\nKeep temporary references to the fs roots associated during recovery. On\nfailure, clear their reloc_root pointers and drop the corresponding\nreferences. Once the first transaction commit succeeds, drop only the\ntemporary fs root references and let the normal merge and cleanup paths\nhandle the relocation roots.\n\nFault injection on a pending-relocation image confirmed the cleanup gap.\nWith an injected first-commit failure, 25 fs roots had reloc_root set with\nfs_error=0. With this fix, the same failure path drops that count to 0\nbefore mount fails."}],"providerMetadata":{"dateUpdated":"2026-09-11T19:45:37.016Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/2256d6dc5b88841a8a8b4fd9a9f04730705fb6fd"},{"url":"https://git.kernel.org/stable/c/8a64baeb5bbb706b83d2235c1e39f5b77183817f"},{"url":"https://git.kernel.org/stable/c/4d43107e807bcd92621106b07f5011411c6341a8"},{"url":"https://git.kernel.org/stable/c/6d8ba4572922e336f0b59a80751b018e1e135164"}],"title":"btrfs: drop recovered reloc root refs on recovery failure","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-89645","datePublished":"2026-09-11T19:45:37.016Z","dateReserved":"2026-09-11T19:38:34.741Z","dateUpdated":"2026-09-11T19:45:37.016Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-11 20:19:50","lastModifiedDate":"2026-09-11 20:19:50","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"89645","Ordinal":"1","Title":"btrfs: drop recovered reloc root refs on recovery failure","CVE":"CVE-2026-89645","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"89645","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: drop recovered reloc root refs on recovery failure\n\nDuring relocation recovery, each fs root gets a reference to its relocation\nroot. If loading or adding a later root fails, or if the first transaction\ncommit fails, btrfs_recover_relocation() jumps to out_unset before\nmerge_reloc_roots() and clean_dirty_subvols().\n\nput_reloc_control() drops the list-owned relocation root references, but it\ndoes not clear fs_root->reloc_root or drop the references owned by those\npointers. Mount cleanup only drops them when BTRFS_FS_ERROR is set, so an\nerror such as -ENOMEM while processing a later root can leave references\nbehind.\n\nKeep temporary references to the fs roots associated during recovery. On\nfailure, clear their reloc_root pointers and drop the corresponding\nreferences. Once the first transaction commit succeeds, drop only the\ntemporary fs root references and let the normal merge and cleanup paths\nhandle the relocation roots.\n\nFault injection on a pending-relocation image confirmed the cleanup gap.\nWith an injected first-commit failure, 25 fs roots had reloc_root set with\nfs_error=0. With this fix, the same failure path drops that count to 0\nbefore mount fails.","Type":"Description","Title":"btrfs: drop recovered reloc root refs on recovery failure"}]}}}