CVE-2026-98244: 
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2026-98244 is a Linux kernel vulnerability in the Btrfs filesystem subsystem where btrfs_rebuild_free_space_tree() fails to clear the BTRFS_FS_CREATING_FREE_SPACE_TREE flag on certain error paths, including the transaction restart failure path. This can leave the flag set on a live filesystem, causing delayed reference processing to be skipped. The vulnerability affects Linux kernel versions starting from 6.14 up to the fixed commits, and is estimated as Medium severity with an EPSS score of 0.0 (Feedly, EUVD).

Technical details

The root cause is improper state management (CWE-459: Incomplete Cleanup) in the Btrfs free space tree rebuild function. When btrfs_rebuild_free_space_tree() encounters errors — particularly on the transaction restart failure path — it returns without clearing the BTRFS_FS_CREATING_FREE_SPACE_TREE flag it had previously set. This stale flag causes the kernel to skip delayed reference processing on the live filesystem, which can lead to inconsistent free space accounting. The BTRFS_FS_FREE_SPACE_TREE_UNTRUSTED flag is intentionally preserved after a failed rebuild, requiring callers to fall back to extent-tree caching (Feedly, Linux Kernel CVE Announce).

Impact

A failed free space tree rebuild that leaves BTRFS_FS_CREATING_FREE_SPACE_TREE set can cause delayed reference processing to be silently skipped on a live Btrfs filesystem. This primarily affects filesystem integrity and availability — free space accounting may become inconsistent, potentially leading to data corruption, erroneous space allocation decisions, or filesystem instability. The impact is local in nature and does not directly expose sensitive data or enable privilege escalation, but could result in data loss or filesystem unavailability on affected systems (Feedly).

Exploitability

There is no known public proof-of-concept exploit, no evidence of in-the-wild exploitation, and no threat actor attribution associated with CVE-2026-98244. The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation would require local access to a system running an affected kernel version with Btrfs and the ability to trigger a free space tree rebuild failure (Feedly, EUVD).

Mitigation and workarounds

The fix has been applied in Linux kernel versions 6.18.54, 7.2.8, and 7.3-rc4, which clear the BTRFS_FS_CREATING_FREE_SPACE_TREE flag on all free space tree rebuild failure paths. Administrators running kernel 6.14 or later (up to the fixed versions) on systems using Btrfs should upgrade to a patched kernel release. As a workaround, avoiding operations that trigger free space tree rebuilds (e.g., mounting with --repair or rescue= options) may reduce exposure until a patch can be applied (Feedly, Kernel Patch 1, Kernel Patch 2, Kernel Patch 3).

Additional resources


Source: This report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-98274NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesOct 06, 2026
CVE-2026-98259NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel6.18
NoYesOct 06, 2026
CVE-2026-98244NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel6.18
NoYesOct 06, 2026
CVE-2026-98240NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesOct 06, 2026
CVE-2026-98226NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management