---
id: CVE-2026-89772
title: 'kernel: btrfs: write-protect folios during data writeback (CVE-2026-89772)'
summary: >-
  A flaw was found in the Btrfs filesystem of the Linux kernel. This
  vulnerability allows a local attacker with write access to a memory-mapped
  file to modify data while it is being written to disk. This can lead to data
  corruption, where th…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: vendor
cwe: CWE-413
vendor: Red Hat
product: Red Hat OpenShift Container Platform 4
affected:
  - openshift_container_platform 4
published: '2026-09-11'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T20:53:53+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89772.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89772.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-89772'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532151'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-89772'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-89772'
  - url: >-
      https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89772.mbox
  - url: 'https://git.kernel.org/stable/c/074c715e0b498891c09fe7f11e1cd9d7a04699bd'
  - url: 'https://git.kernel.org/stable/c/5376c9db45368eb210b4d71104ac00a59dc8b6e0'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
epss: 0.00176
epssPercentile: 0.07411
ingestedAt: '2026-09-14T11:11:19.884Z'
---

## Overview

A flaw was found in the Btrfs filesystem of the Linux kernel. This vulnerability allows a local attacker with write access to a memory-mapped file to modify data while it is being written to disk. This can lead to data corruption, where the integrity of the stored information is compromised, or data loss, where recent changes to a file are not saved correctly even after a save operation. The issue arises from a missing write-protection mechanism during specific data writeback operations.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89772.json)

**kernel: btrfs: write-protect folios during data writeback** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-15.

Affected:

- Red Hat OpenShift Container Platform 4

No fix planned:

- Red Hat OpenShift Container Platform 4

## Remediation

Fix deferred
