CVE-2026-89644
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/09/2026
Last modified:
21/09/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
btrfs: fix extent map leak in NOCOW direct I/O write<br />
<br />
btrfs_dio_iomap_begin() calls btrfs_get_extent(), which returns an<br />
extent map reference that must be dropped on all exit paths.<br />
<br />
For direct writes into a NOCOW range, btrfs_get_blocks_direct_write()<br />
keeps using that extent map and asks btrfs_create_dio_extent() to<br />
allocate the ordered extent. If that fails, for example because<br />
btrfs_alloc_ordered_extent() fails, the function returns the error<br />
without dropping the input extent map. The PREALLOC path avoided this by<br />
dropping the input extent map before replacing it with the newly created<br />
one.<br />
<br />
Check the error from btrfs_create_dio_extent() before replacing the<br />
map and drop the input extent map on failure.


