{"id":"CVE-2026-93798","published":"2026-09-24T17:17:12.607","lastModified":"2026-09-25T13:17:20.537","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix reloc root cleanup in merge_reloc_roots()\n\nIf the root we got has zero root refs in its root item, we are resetting\nthe root's ->reloc_root without using barriers like we do everywhere else.\nSashiko complained about this while reviewing another patch, and it's\ncorrect (see the Link tag below).\n\nAlso, we should not clear BTRFS_ROOT_DEAD_RELOC_TREE from the root unless\nthe root points to the reloc root we have.\n\nFix this by using clear_reloc_root(), which issues the memory barrier\nafter setting the root's ->reloc_root to NULL and before clearing the bit\nBTRFS_ROOT_DEAD_RELOC_TREE from the root.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/63d6b1f04cd91c825329712aa526215ffa5d11ca","tags":[]},{"url":"https://git.kernel.org/stable/c/ab48583aa9948205ff9a6470e23dbff74c565e24","tags":[]},{"url":"https://git.kernel.org/stable/c/b78fe9563e2d5ae47805f1e5dc722c91fd30e1f8","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}