{"api_version":"1","generated_at":"2026-09-30T23:27:05+00:00","cve":"CVE-2026-93800","urls":{"html":"https://cve.report/CVE-2026-93800","api":"https://cve.report/api/cve/CVE-2026-93800.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93800","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93800"},"summary":{"title":"btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()\n\nIf during relocation we fail in insert_dirty_subvol() because\nbtrfs_update_reloc_root() returned an error, we will leave a root's\nreloc_root field pointing to a reloc root that was freed instead of NULL,\nresulting later in a use-after-free, or double free attempt during\nunmount.\n\nThe sequence of steps is this:\n\n1) During relocation the call to btrfs_update_reloc_root() in\n   insert_dirty_subvol() fails, so insert_dirty_subvol() returns the\n   error to merge_reloc_root() without adding the root to the list\n   rc->dirty_subvol_roots;\n\n2) Then merge_reloc_root() aborts the current transaction because\n   insert_dirty_subvol() returned an error;\n\n3) Up the call chain, merge_reloc_roots() gets the error, adds the\n   reloc root for root X to the local reloc_roots list and jumps to the\n   'out' label, where it calls free_reloc_roots() to free all the reloc\n   roots in the local reloc_roots list. This frees the reloc root for\n   root X;\n\n4) We go up the call chain to relocate_block_group() which calls\n   clean_dirty_subvols() to go over dirty roots and set their\n   ->reloc_root field to NULL, but root X is not in the dirty_subvol_roots\n   list, so its ->reloc_root still points to a reloc root;\n\n5) Relocation finishes, with an error and a transaction abort, but the\n   ->reloc_root field for root X still points to the reloc root that was\n   freed in step 3;\n\n6) When unmounting the fs we end up calling:\n\n     btrfs_free_fs_roots()\n        btrfs_drop_and_free_fs_root()\n           --> calls btrfs_put_root() against root X's ->reloc_root\n               which is not NULL and points to the already freed\n               reloc root in step 4 above\n\n  Resulting in a use-after-free to a double free attempt.\n\nSyzbot reported this with the following dmesg/syslog:\n\n   [  106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)\n   [  106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure\n   [  106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5\n   [  106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.\n   [  106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0\n   [  106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure\n   [  106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly\n   [  106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure\n   [  106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1\n   [  106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30\n   [  106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30\n   [  106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409\n   [  106.682946][ T5338] ==================================================================\n   [  106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250\n   [  106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338\n   [  106.693173][ T5338]\n   [  106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)\n   [  106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n   [  106.694300][ T5338] Call Trace:\n   [  106.694308][ T5338]  <TASK>\n   [  106.694314][ T5338]  dump_stack_lvl+0xe8/0x150\n   [  106.694331][ T5338]  print_address_description+0x55/0x1e0\n   [  106.694343][ T5338]  ? btrfs_put_root+0x2f/0x250\n   [  106.694358][ T5338]  print_report+0x58/0x70\n   [  106.\n---truncated---","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 17:17:12","updated_at":"2026-09-25 13:17:20"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/fda1b6636ff1846f00643e791099db5564b547d9","name":"https://git.kernel.org/stable/c/fda1b6636ff1846f00643e791099db5564b547d9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/97a540d72ebcb21853d11f2a56782fe377f358e7","name":"https://git.kernel.org/stable/c/97a540d72ebcb21853d11f2a56782fe377f358e7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/83201804efa4a5168be754e1dfc9b2faee760cac","name":"https://git.kernel.org/stable/c/83201804efa4a5168be754e1dfc9b2faee760cac","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93800","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93800","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 592fbcd50c99b8adf999a2a54f9245caff333139 97a540d72ebcb21853d11f2a56782fe377f358e7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 592fbcd50c99b8adf999a2a54f9245caff333139 fda1b6636ff1846f00643e791099db5564b547d9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 592fbcd50c99b8adf999a2a54f9245caff333139 83201804efa4a5168be754e1dfc9b2faee760cac git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected f32b84d7c977e1906a4781b93b3c93090b6cd675 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected aa18bc1ff8a51f082d5b3b6d07693797637b4028 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4cb0aea2e250eee35ccfac5f5395cd8f3238a9e5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.10.36 5.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.11.20 5.12 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.12.3 5.13 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.13","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.13 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"93800","cve":"CVE-2026-93800","epss":"0.001660000","percentile":"0.052210000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"97a540d72ebcb21853d11f2a56782fe377f358e7","status":"affected","version":"592fbcd50c99b8adf999a2a54f9245caff333139","versionType":"git"},{"lessThan":"fda1b6636ff1846f00643e791099db5564b547d9","status":"affected","version":"592fbcd50c99b8adf999a2a54f9245caff333139","versionType":"git"},{"lessThan":"83201804efa4a5168be754e1dfc9b2faee760cac","status":"affected","version":"592fbcd50c99b8adf999a2a54f9245caff333139","versionType":"git"},{"status":"affected","version":"f32b84d7c977e1906a4781b93b3c93090b6cd675","versionType":"git"},{"status":"affected","version":"aa18bc1ff8a51f082d5b3b6d07693797637b4028","versionType":"git"},{"status":"affected","version":"4cb0aea2e250eee35ccfac5f5395cd8f3238a9e5","versionType":"git"},{"lessThan":"5.11","status":"affected","version":"5.10.36","versionType":"semver"},{"lessThan":"5.12","status":"affected","version":"5.11.20","versionType":"semver"},{"lessThan":"5.13","status":"affected","version":"5.12.3","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.13"},{"lessThan":"5.13","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","versionStartIncluding":"5.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","versionStartIncluding":"5.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.13","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.36","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11.20","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.12.3","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()\n\nIf during relocation we fail in insert_dirty_subvol() because\nbtrfs_update_reloc_root() returned an error, we will leave a root's\nreloc_root field pointing to a reloc root that was freed instead of NULL,\nresulting later in a use-after-free, or double free attempt during\nunmount.\n\nThe sequence of steps is this:\n\n1) During relocation the call to btrfs_update_reloc_root() in\n   insert_dirty_subvol() fails, so insert_dirty_subvol() returns the\n   error to merge_reloc_root() without adding the root to the list\n   rc->dirty_subvol_roots;\n\n2) Then merge_reloc_root() aborts the current transaction because\n   insert_dirty_subvol() returned an error;\n\n3) Up the call chain, merge_reloc_roots() gets the error, adds the\n   reloc root for root X to the local reloc_roots list and jumps to the\n   'out' label, where it calls free_reloc_roots() to free all the reloc\n   roots in the local reloc_roots list. This frees the reloc root for\n   root X;\n\n4) We go up the call chain to relocate_block_group() which calls\n   clean_dirty_subvols() to go over dirty roots and set their\n   ->reloc_root field to NULL, but root X is not in the dirty_subvol_roots\n   list, so its ->reloc_root still points to a reloc root;\n\n5) Relocation finishes, with an error and a transaction abort, but the\n   ->reloc_root field for root X still points to the reloc root that was\n   freed in step 3;\n\n6) When unmounting the fs we end up calling:\n\n     btrfs_free_fs_roots()\n        btrfs_drop_and_free_fs_root()\n           --> calls btrfs_put_root() against root X's ->reloc_root\n               which is not NULL and points to the already freed\n               reloc root in step 4 above\n\n  Resulting in a use-after-free to a double free attempt.\n\nSyzbot reported this with the following dmesg/syslog:\n\n   [  106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)\n   [  106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure\n   [  106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5\n   [  106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.\n   [  106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0\n   [  106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure\n   [  106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly\n   [  106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure\n   [  106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1\n   [  106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30\n   [  106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30\n   [  106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409\n   [  106.682946][ T5338] ==================================================================\n   [  106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250\n   [  106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338\n   [  106.693173][ T5338]\n   [  106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)\n   [  106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n   [  106.694300][ T5338] Call Trace:\n   [  106.694308][ T5338]  <TASK>\n   [  106.694314][ T5338]  dump_stack_lvl+0xe8/0x150\n   [  106.694331][ T5338]  print_address_description+0x55/0x1e0\n   [  106.694343][ T5338]  ? btrfs_put_root+0x2f/0x250\n   [  106.694358][ T5338]  print_report+0x58/0x70\n   [  106.\n---truncated---"}],"providerMetadata":{"dateUpdated":"2026-09-25T12:43:07.322Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/97a540d72ebcb21853d11f2a56782fe377f358e7"},{"url":"https://git.kernel.org/stable/c/fda1b6636ff1846f00643e791099db5564b547d9"},{"url":"https://git.kernel.org/stable/c/83201804efa4a5168be754e1dfc9b2faee760cac"}],"title":"btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93800","datePublished":"2026-09-24T16:02:34.370Z","dateReserved":"2026-09-18T17:59:28.789Z","dateUpdated":"2026-09-25T12:43:07.322Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 17:17:12","lastModifiedDate":"2026-09-25 13:17:20","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93800","Ordinal":"1","Title":"btrfs: fix use-after-free on reloc root after error in insert_di","CVE":"CVE-2026-93800","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93800","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free on reloc root after error in insert_dirty_subvol()\n\nIf during relocation we fail in insert_dirty_subvol() because\nbtrfs_update_reloc_root() returned an error, we will leave a root's\nreloc_root field pointing to a reloc root that was freed instead of NULL,\nresulting later in a use-after-free, or double free attempt during\nunmount.\n\nThe sequence of steps is this:\n\n1) During relocation the call to btrfs_update_reloc_root() in\n   insert_dirty_subvol() fails, so insert_dirty_subvol() returns the\n   error to merge_reloc_root() without adding the root to the list\n   rc->dirty_subvol_roots;\n\n2) Then merge_reloc_root() aborts the current transaction because\n   insert_dirty_subvol() returned an error;\n\n3) Up the call chain, merge_reloc_roots() gets the error, adds the\n   reloc root for root X to the local reloc_roots list and jumps to the\n   'out' label, where it calls free_reloc_roots() to free all the reloc\n   roots in the local reloc_roots list. This frees the reloc root for\n   root X;\n\n4) We go up the call chain to relocate_block_group() which calls\n   clean_dirty_subvols() to go over dirty roots and set their\n   ->reloc_root field to NULL, but root X is not in the dirty_subvol_roots\n   list, so its ->reloc_root still points to a reloc root;\n\n5) Relocation finishes, with an error and a transaction abort, but the\n   ->reloc_root field for root X still points to the reloc root that was\n   freed in step 3;\n\n6) When unmounting the fs we end up calling:\n\n     btrfs_free_fs_roots()\n        btrfs_drop_and_free_fs_root()\n           --> calls btrfs_put_root() against root X's ->reloc_root\n               which is not NULL and points to the already freed\n               reloc root in step 4 above\n\n  Resulting in a use-after-free to a double free attempt.\n\nSyzbot reported this with the following dmesg/syslog:\n\n   [  106.004389][ T5339] BTRFS error (device loop0 state A): Transaction aborted (error -5)\n   [  106.014266][ T5339] BTRFS: error (device loop0 state A) in merge_reloc_root:1655: errno=-5 IO failure\n   [  106.021891][ T1061] BTRFS error (device loop0 state A): error while writing out transaction: -5\n   [  106.026964][ T1061] BTRFS warning (device loop0 state A): Skipping commit of aborted transaction.\n   [  106.033807][ T5340] BTRFS error (device loop0 state A): bdev /dev/loop0 errs: wr 3, rd 0, flush 0, corrupt 0, gen 0\n   [  106.039265][ T1061] BTRFS: error (device loop0 state A) in cleanup_transaction:2067: errno=-5 IO failure\n   [  106.044382][ T5339] BTRFS info (device loop0 state EA): forced readonly\n   [  106.074329][ T5339] BTRFS: error (device loop0 state EA) in merge_reloc_roots:1887: errno=-5 IO failure\n   [  106.081004][ T5356] BTRFS info (device loop0 state EA): scrub: started on devid 1\n   [  106.085611][ T5339] BTRFS info (device loop0 state EA): balance: ended with status: -30\n   [  106.089517][ T5356] BTRFS info (device loop0 state EA): scrub: not finished on devid 1 with status: -30\n   [  106.662365][ T5338] BTRFS info (device loop0 state EA): last unmount of filesystem 3a375e4e-b156-4d76-a2ad-16e198ce1409\n   [  106.682946][ T5338] ==================================================================\n   [  106.686574][ T5338] BUG: KASAN: slab-use-after-free in btrfs_put_root+0x2f/0x250\n   [  106.690090][ T5338] Write of size 4 at addr ffff88803f978630 by task syz.0.0/5338\n   [  106.693173][ T5338]\n   [  106.694279][ T5338] CPU: 0 UID: 0 PID: 5338 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)\n   [  106.694293][ T5338] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n   [  106.694300][ T5338] Call Trace:\n   [  106.694308][ T5338]  <TASK>\n   [  106.694314][ T5338]  dump_stack_lvl+0xe8/0x150\n   [  106.694331][ T5338]  print_address_description+0x55/0x1e0\n   [  106.694343][ T5338]  ? btrfs_put_root+0x2f/0x250\n   [  106.694358][ T5338]  print_report+0x58/0x70\n   [  106.\n---truncated---","Type":"Description","Title":"btrfs: fix use-after-free on reloc root after error in insert_di"}]}}}