← All Advisories

CVE-2026-98083

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98083

Key Details

CVECVE-2026-98083
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-10-03
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

btrfs: fix transaction use-after-free in raid stripe insertion

If allocation of a RAID stripe extent fails,

btrfs_insert_one_raid_extent() aborts and ends the transaction before

returning -ENOMEM.

btrfs_finish_one_ordered(), the production caller through

btrfs_insert_raid_extent(), still owns the transaction handle. It handles

the error by aborting the transaction and then reaches the common exit

path, which ends the transaction again.

The premature end can free the handle and drop its transaction reference.

Transaction cleanup can then free the transaction before the caller's

second abort accesses the handle and transaction, resulting in

use-after-free.

Keep the abort at the failure site, but let the caller's common exit path

end the transaction once, after it has finished using both objects. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98083
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98083