
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-98244 is a Linux kernel vulnerability in the Btrfs filesystem subsystem where btrfs_rebuild_free_space_tree() fails to clear the BTRFS_FS_CREATING_FREE_SPACE_TREE flag on certain error paths, including the transaction restart failure path. This can leave the flag set on a live filesystem, causing delayed reference processing to be skipped. The vulnerability affects Linux kernel versions starting from 6.14 up to the fixed commits, and is estimated as Medium severity with an EPSS score of 0.0 (Feedly, EUVD).
The root cause is improper state management (CWE-459: Incomplete Cleanup) in the Btrfs free space tree rebuild function. When btrfs_rebuild_free_space_tree() encounters errors — particularly on the transaction restart failure path — it returns without clearing the BTRFS_FS_CREATING_FREE_SPACE_TREE flag it had previously set. This stale flag causes the kernel to skip delayed reference processing on the live filesystem, which can lead to inconsistent free space accounting. The BTRFS_FS_FREE_SPACE_TREE_UNTRUSTED flag is intentionally preserved after a failed rebuild, requiring callers to fall back to extent-tree caching (Feedly, Linux Kernel CVE Announce).
A failed free space tree rebuild that leaves BTRFS_FS_CREATING_FREE_SPACE_TREE set can cause delayed reference processing to be silently skipped on a live Btrfs filesystem. This primarily affects filesystem integrity and availability — free space accounting may become inconsistent, potentially leading to data corruption, erroneous space allocation decisions, or filesystem instability. The impact is local in nature and does not directly expose sensitive data or enable privilege escalation, but could result in data loss or filesystem unavailability on affected systems (Feedly).
There is no known public proof-of-concept exploit, no evidence of in-the-wild exploitation, and no threat actor attribution associated with CVE-2026-98244. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation would require local access to a system running an affected kernel version with Btrfs and the ability to trigger a free space tree rebuild failure (Feedly, EUVD).
The fix has been applied in Linux kernel versions 6.18.54, 7.2.8, and 7.3-rc4, which clear the BTRFS_FS_CREATING_FREE_SPACE_TREE flag on all free space tree rebuild failure paths. Administrators running kernel 6.14 or later (up to the fixed versions) on systems using Btrfs should upgrade to a patched kernel release. As a workaround, avoiding operations that trigger free space tree rebuilds (e.g., mounting with --repair or rescue= options) may reduce exposure until a patch can be applied (Feedly, Kernel Patch 1, Kernel Patch 2, Kernel Patch 3).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."