← All Advisories

CVE-2026-98090

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98090

Key Details

CVECVE-2026-98090
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

btrfs: restore active device pointers after failed sprout

btrfs_init_new_device() switches latest_dev and possibly s_bdev from the

seed device to the new sprout device before creating the first writable

chunks.

If chunk creation or the subsequent sprout setup fails, the error path

releases the new device without switching those pointers back.

btrfs_show_devname() can then dereference the freed latest_dev and crash.

Restore the active device pointers to the latest seed device before

removing and releasing the failed sprout device. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98090
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98090