---
id: CVE-2026-98244
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  btrfs: clear free space tree creation state on rebuild failure

  btrfs_rebuild_free_space_tree() sets BTRFS_FS_CREATING_FREE_SPACE_TREE
  before rebuilding the free space …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  btrfs: clear free space tree creation state on rebuild failure

  btrfs_rebuild_free_space_tree() sets BTRFS_FS_CREATING_FREE_SPACE_TREE
  before rebuilding the free space …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 882af9f13e830c0a4ef696bb72cd5998a5067a93 <
    a32bedab8ece9d1f90a1476a5b486a1804dc78ba
  - >-
    Linux >= 882af9f13e830c0a4ef696bb72cd5998a5067a93 <
    b1df2997d0cd2be7bef7b4ab64ccfd1019dedc81
  - >-
    Linux >= 882af9f13e830c0a4ef696bb72cd5998a5067a93 <
    3565893cc72cdf6b795cf6a33e7ff9605322334d
  - Linux 6.14
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:12.510'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98244'
references:
  - url: 'https://git.kernel.org/stable/c/3565893cc72cdf6b795cf6a33e7ff9605322334d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a32bedab8ece9d1f90a1476a5b486a1804dc78ba'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b1df2997d0cd2be7bef7b4ab64ccfd1019dedc81'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.432Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

btrfs: clear free space tree creation state on rebuild failure

btrfs_rebuild_free_space_tree() sets BTRFS_FS_CREATING_FREE_SPACE_TREE
before rebuilding the free space tree.  Several error paths return
without clearing this flag.

The transaction restart failure path can leave the flag set on a live
filesystem, causing delayed reference processing to be skipped. Clear it
on all free space tree rebuild failure paths. Keep
BTRFS_FS_FREE_SPACE_TREE_UNTRUSTED set, since a failed rebuild leaves
the free space tree untrusted. Callers must fall back to extent-tree
caching.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
