CVE-2026-98269 PUBLISHED

btrfs: abort transaction on failure to update inode for hole punching and reflinking

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

btrfs: abort transaction on failure to update inode for hole punching and reflinking

If we fail to update the inode we error out without aborting the transaction, which can result in a persistent inconsistency if after the failure the transaction is committed, as we have dropped file extent items from a range and either punched a hole or insert a new file extent item for that range (for reflinks).

So add the missing transaction abort.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 2aaa66558172b017f36bf38ae69372813dedee9d to 2605eb9ba3bbd4c9f455cfe6b85bd28a1da7067d (excl.)
  • affected from 2aaa66558172b017f36bf38ae69372813dedee9d to 834a3b5c5f1ec0df48c1a6208f9989f4ffdaa0b6 (excl.)
  • affected from 2aaa66558172b017f36bf38ae69372813dedee9d to 9588850bfa75c78ce73c2f6f72544d19d2e9beb6 (excl.)
  • affected from 2aaa66558172b017f36bf38ae69372813dedee9d to 36c68dc909845c049e0286d229bc502947239452 (excl.)
  • affected from 2aaa66558172b017f36bf38ae69372813dedee9d to 97fcd34aa9fd73cefe3120ac9a82ca9d7763922f (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.7 is affected
  • unaffected from 0 to 3.7 (excl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References