CVE-2026-98245

Source
https://cve.org/CVERecord?id=CVE-2026-98245
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98245.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98245
Downstream
Published
2026-10-06T08:45:14Z
Modified
2026-10-07T02:47:30Z
Summary
btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()
Details

In the Linux kernel, the following vulnerability has been resolved:

btrfs: take commit root semaphore when iterating in mark_block_group_to_copy()

mark_block_group_to_copy() iterates over the commit root with skip_locking=true. A concurrent transaction commit can swap and free the commit root during iteration, causing use-after-free when accessing extent buffers.

Fix it by using path->need_commit_sem to protect the commit root search.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98245.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
78ce9fc269af6e69c1399ab910ba6bc81c934f67
Fixed
8e2007b263ea250251ec3021a0a197da990ee1a8
Fixed
709f6a5e986535005110c6c69b322f63631cb200
Fixed
c32490c6d3f3a9f2d177d57c7eb8bbc347561d08
Fixed
0594e3423f4ba3137c734371169491f9a98e9af4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98245.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.12.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98245.json"