{"id":"CVE-2026-98091","published":"2026-09-25T11:17:38.807","lastModified":"2026-09-25T11:17:38.807","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: detach failed sprout device from transaction update list\n\nWhen creating the first metadata chunk for a sprout filesystem,\ncreate_chunk() adds the new device to the transaction dev_update_list\nthrough device->post_commit_list.\n\nIf the subsequent system chunk creation fails, btrfs_init_new_device()\naborts the transaction and releases the device while post_commit_list is\nstill linked. This triggers a warning in btrfs_free_device() and leaves\nthe transaction list referencing freed memory.\n\nDetach the device while holding chunk_mutex before releasing it.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/0ea6814bc0ff7cff443241bd34db9f0f828f3190","tags":[]},{"url":"https://git.kernel.org/stable/c/8b001df2b37ca022f710f3254fbb0bcd6d9e1bed","tags":[]},{"url":"https://git.kernel.org/stable/c/c93b3c43df561cd9f592cee20ae058b563f9e5b6","tags":[]},{"url":"https://git.kernel.org/stable/c/e9e7e37afa85db770e6084360b21a21a8b3a583f","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}