CVE-2026-68422

low

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() If we have an unexpected reloc_root for our root, we jump to the out label but never drop the reference we obtained for root, resulting in a leak. Add a missing btrfs_put_root() call.

References

https://git.kernel.org/stable/c/f89df93e8aefa4c1c813f835559f2ac727f79766

https://git.kernel.org/stable/c/ce6050bafb4e33377dc17fcc357736bfc351180c

https://git.kernel.org/stable/c/b3d39b03799600c76c33486e2d29b73a771023db

https://git.kernel.org/stable/c/7591d1727067d6063247901ad25c4bdc4e5695c4

https://git.kernel.org/stable/c/72f673d1c1deb819554d3e7e154f6d84301eb735

https://git.kernel.org/stable/c/60a23d4ea169e27403f3bb023bb98036797c0206

https://git.kernel.org/stable/c/3f586b4c92e4272fcd01bf0db0590b63acf3e85b

Details

Source: Mitre, NVD

Published: 2026-08-10

Updated: 2026-08-19

Risk Information

CVSS v2

Base Score: 1.7

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 3.3

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Severity: Low

EPSS

EPSS: 0.00209