CVE-2026-68422

high

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() If we have an unexpected reloc_root for our root, we jump to the out label but never drop the reference we obtained for root, resulting in a leak. Add a missing btrfs_put_root() call.

References

https://git.kernel.org/stable/c/ce6050bafb4e33377dc17fcc357736bfc351180c

https://git.kernel.org/stable/c/b3d39b03799600c76c33486e2d29b73a771023db

https://git.kernel.org/stable/c/7591d1727067d6063247901ad25c4bdc4e5695c4

https://git.kernel.org/stable/c/72f673d1c1deb819554d3e7e154f6d84301eb735

https://git.kernel.org/stable/c/60a23d4ea169e27403f3bb023bb98036797c0206

Details

Source: Mitre, NVD

Published: 2026-08-10

Updated: 2026-08-10

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High