{"id":"CVE-2026-98083","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix transaction use-after-free in raid stripe insertion\n\nIf allocation of a RAID stripe extent fails,\nbtrfs_insert_one_raid_extent() aborts and ends the transact…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix transaction use-after-free in raid stripe insertion\n\nIf allocation of a RAID stripe extent fails,\nbtrfs_insert_one_raid_extent() aborts and ends the transact…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 02c372e1f016e5113217597ab37b399c4e407477 < b185bdf30313e213fa1c887fe22fc3d513c061d9","Linux >= 02c372e1f016e5113217597ab37b399c4e407477 < 2fbfd02bdfe12b20bd3cc7a3190fb32e3f7072f5","Linux >= 02c372e1f016e5113217597ab37b399c4e407477 < b7b94923b3b5774d85a2a7c8d6eb9e3e0ef66685","Linux >= 02c372e1f016e5113217597ab37b399c4e407477 < a8813a923f9e43f788b357fb55c35f7f6ed6f98c","Linux ab69bf6f8970c09d3735c25094e9471d54365282","Linux >= 6.6.130 < 6.7","Linux 6.7"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T15:18:05.703","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98083","references":[{"url":"https://git.kernel.org/stable/c/2fbfd02bdfe12b20bd3cc7a3190fb32e3f7072f5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a8813a923f9e43f788b357fb55c35f7f6ed6f98c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b185bdf30313e213fa1c887fe22fc3d513c061d9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b7b94923b3b5774d85a2a7c8d6eb9e3e0ef66685","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-25T11:06:38.836Z","slug":"CVE-2026-98083","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix transaction use-after-free in raid stripe insertion\n\nIf allocation of a RAID stripe extent fails,\nbtrfs_insert_one_raid_extent() aborts and ends the transaction before\nreturning -ENOMEM.\n\nbtrfs_finish_one_ordered(), the production caller through\nbtrfs_insert_raid_extent(), still owns the transaction handle. It handles\nthe error by aborting the transaction and then reaches the common exit\npath, which ends the transaction again.\n\nThe premature end can free the handle and drop its transaction reference.\nTransaction cleanup can then free the transaction before the caller's\nsecond abort accesses the handle and transaction, resulting in\nuse-after-free.\n\nKeep the abort at the failure site, but let the caller's common exit path\nend the transaction once, after it has finished using both objects.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":210906,"id":"CVE-2026-98083","ts":1790349114571,"field":"cvss","old":null,"new":"7"},{"seq":210905,"id":"CVE-2026-98083","ts":1790349114571,"field":"severity","old":"none","new":"high"}]}