---
id: CVE-2026-98269
title: >-
  In the Linux kernel, the following vulnerability has been resolved:


  btrfs: abort transaction on failure to update inode for hole punching and
  reflinking


  If we fail to update the inode we error out without aborting the

  transaction, whic…
summary: >-
  In the Linux kernel, the following vulnerability has been resolved:


  btrfs: abort transaction on failure to update inode for hole punching and
  reflinking


  If we fail to update the inode we error out without aborting the

  transaction, whic…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 2aaa66558172b017f36bf38ae69372813dedee9d <
    2605eb9ba3bbd4c9f455cfe6b85bd28a1da7067d
  - >-
    Linux >= 2aaa66558172b017f36bf38ae69372813dedee9d <
    834a3b5c5f1ec0df48c1a6208f9989f4ffdaa0b6
  - >-
    Linux >= 2aaa66558172b017f36bf38ae69372813dedee9d <
    9588850bfa75c78ce73c2f6f72544d19d2e9beb6
  - >-
    Linux >= 2aaa66558172b017f36bf38ae69372813dedee9d <
    36c68dc909845c049e0286d229bc502947239452
  - >-
    Linux >= 2aaa66558172b017f36bf38ae69372813dedee9d <
    97fcd34aa9fd73cefe3120ac9a82ca9d7763922f
  - Linux 3.7
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:16.353'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98269'
references:
  - url: 'https://git.kernel.org/stable/c/2605eb9ba3bbd4c9f455cfe6b85bd28a1da7067d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/36c68dc909845c049e0286d229bc502947239452'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/834a3b5c5f1ec0df48c1a6208f9989f4ffdaa0b6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9588850bfa75c78ce73c2f6f72544d19d2e9beb6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/97fcd34aa9fd73cefe3120ac9a82ca9d7763922f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.423Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

btrfs: abort transaction on failure to update inode for hole punching and reflinking

If we fail to update the inode we error out without aborting the
transaction, which can result in a persistent inconsistency if after
the failure the transaction is committed, as we have dropped file
extent items from a range and either punched a hole or insert a new file
extent item for that range (for reflinks).

So add the missing transaction abort.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
