Use-After-Free Vulnerability in Linux Kernel Btrfs RAID Handling
CVE-2026-98083

7HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-98083?

A use-after-free vulnerability exists in the Linux kernel, specifically within the btrfs filesystem's RAID stripe insertion routine. When the allocation of a RAID stripe extent fails, the function btrfs_insert_one_raid_extent() aborts the transaction prematurely. The issue arises in the handling of transaction references, as subsequent calls can free references before the operation complete. This flaw can potentially be exploited to access freed memory regions, leading to unstable system behavior or possible information exposure. Proper error handling measures must be implemented to mitigate this risk.

Affected Version(s)

Linux ab69bf6f8970c09d3735c25094e9471d54365282 < 089d9c45ea49ffffe55a8fe08d0ce2536626e90a

Linux 02c372e1f016e5113217597ab37b399c4e407477

Linux 02c372e1f016e5113217597ab37b399c4e407477 < 2fbfd02bdfe12b20bd3cc7a3190fb32e3f7072f5

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.