From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C0ED258B6BB for ; Fri, 11 Sep 2026 20:00:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156843; cv=none; b=gW8JFu566hNnKQETRxa2dK93kegiZUK8eigc+6cd4sGBmGMSgh8iHySDwWA0ODIn0q50OIgw1cL1XopyvA/VT/cirEQsWp6xs4ouMAXpBHGq8zM84Cth84XIcnlfL5t7RPQ6q+2Mzp2TFGlGxMjIlMCakqPg2BLNZ//eNGmbkW0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156843; c=relaxed/simple; bh=W22w5HjqKLsT3AvWLpl54XSNGr0yMhI7MuVAjEU7tXI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=fEJVUDO5lhKeedvib+eIEci1QiT0S9ab3kxmJYT9PLahjXFMqDJJxDTP07aQocSOlZYL2W3yhElYjBMkMBKfmGsIxstoGheeIwfaJz+TNMxGAIbt8dWjENM7Wa0wRD2KY44omCzN/RaAeknTWr8nmvu/voCph2Yafej+fVP0M64= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=MKqrbCel; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="MKqrbCel" Received: by smtp.kernel.org (Postfix) with ESMTPSA id EA8301F00893; Fri, 11 Sep 2026 20:00:25 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156826; bh=WLqzg21g6y90OzImTiutduRt24/iYoqSM1/GPlVBKZg=; h=From:To:Cc:Subject:Date:Reply-To; b=MKqrbCel6/H6ts/N00I0n5OcxK3lo/30e4JgxLGzpIYqcLjWIwPV4ySz31fWSBoNe F7rWWPUiPN476IXKOc36rXbeGUbwAxpFSzHYtQN9+EnuCi6N8gsc7/CRFjltwsvMlC c/hDVPcKh6kw2CL0/HhDAgAGdk9AqUzA7zxXghlE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89645: btrfs: drop recovered reloc root refs on recovery failure Date: Fri, 11 Sep 2026 21:45:34 +0200 Message-ID: <2026091143-CVE-2026-89645-da8b@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3361; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=XMvozG29EKaQDpG7/vynWZCIB1KnTpcK3bROr1IN9yI=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIss/tYlr8B9e77w+uefje9mA9Xlfl+5/EFB5Q9TqN eMVQR/JjlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZjIVReG+eETPpltMErTW5+9 hsdIYrr2+ovKPxjmcO5U/+rmtjb04g7L+7cTDZ+bnJTYDQA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: btrfs: drop recovered reloc root refs on recovery failure During relocation recovery, each fs root gets a reference to its relocation root. If loading or adding a later root fails, or if the first transaction commit fails, btrfs_recover_relocation() jumps to out_unset before merge_reloc_roots() and clean_dirty_subvols(). put_reloc_control() drops the list-owned relocation root references, but it does not clear fs_root->reloc_root or drop the references owned by those pointers. Mount cleanup only drops them when BTRFS_FS_ERROR is set, so an error such as -ENOMEM while processing a later root can leave references behind. Keep temporary references to the fs roots associated during recovery. On failure, clear their reloc_root pointers and drop the corresponding references. Once the first transaction commit succeeds, drop only the temporary fs root references and let the normal merge and cleanup paths handle the relocation roots. Fault injection on a pending-relocation image confirmed the cleanup gap. With an injected first-commit failure, 25 fs roots had reloc_root set with fs_error=0. With this fix, the same failure path drops that count to 0 before mount fails. The Linux kernel CVE team has assigned CVE-2026-89645 to this issue. Affected and fixed versions =========================== Issue introduced in 5.7 with commit f44deb7442edf42abee6be25fca7e3e86061b4c9 and fixed in 6.12.109 with commit 2256d6dc5b88841a8a8b4fd9a9f04730705fb6fd Issue introduced in 5.7 with commit f44deb7442edf42abee6be25fca7e3e86061b4c9 and fixed in 6.18.50 with commit 8a64baeb5bbb706b83d2235c1e39f5b77183817f Issue introduced in 5.7 with commit f44deb7442edf42abee6be25fca7e3e86061b4c9 and fixed in 7.2.4 with commit 4d43107e807bcd92621106b07f5011411c6341a8 Issue introduced in 5.7 with commit f44deb7442edf42abee6be25fca7e3e86061b4c9 and fixed in 7.3-rc1 with commit 6d8ba4572922e336f0b59a80751b018e1e135164 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89645 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: fs/btrfs/relocation.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/2256d6dc5b88841a8a8b4fd9a9f04730705fb6fd https://git.kernel.org/stable/c/8a64baeb5bbb706b83d2235c1e39f5b77183817f https://git.kernel.org/stable/c/4d43107e807bcd92621106b07f5011411c6341a8 https://git.kernel.org/stable/c/6d8ba4572922e336f0b59a80751b018e1e135164