CVE-2026-98269

medium

Description

In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on failure to update inode for hole punching and reflinking If we fail to update the inode we error out without aborting the transaction, which can result in a persistent inconsistency if after the failure the transaction is committed, as we have dropped file extent items from a range and either punched a hole or insert a new file extent item for that range (for reflinks). So add the missing transaction abort.

References

https://git.kernel.org/stable/c/97fcd34aa9fd73cefe3120ac9a82ca9d7763922f

https://git.kernel.org/stable/c/9588850bfa75c78ce73c2f6f72544d19d2e9beb6

https://git.kernel.org/stable/c/834a3b5c5f1ec0df48c1a6208f9989f4ffdaa0b6

https://git.kernel.org/stable/c/36c68dc909845c049e0286d229bc502947239452

https://git.kernel.org/stable/c/2605eb9ba3bbd4c9f455cfe6b85bd28a1da7067d

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-93197

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-06

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00175