Answer in brief
CVE-2026-98269 records a Unknown severity vulnerability in btrfs: abort transaction on failure to update inode for hole punching and reflinking. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=2aaa66558172b017f36bf38ae69372813dedee9d <2605eb9ba3bbd4c9f455cfe6b85bd28a1da7067d || >=2aaa66558172b017f36bf38ae69372813dedee9d <834a3b5c5f1ec0df48c1a6208f9989f4ffdaa0b6 || >=2aaa66558172b017f36bf38ae69372813dedee9d <9588850bfa75c78ce73c2f6f72544d19d2e9beb6 || >=2aaa66558172b017f36bf38ae69372813dedee9d <36c68dc909845c049e0286d229bc502947239452 || >=2aaa66558172b017f36bf38ae69372813dedee9d <97fcd34aa9fd73cefe3120ac9a82ca9d7763922f | 2605eb9ba3bbd4c9f455cfe6b85bd28a1da7067d, 834a3b5c5f1ec0df48c1a6208f9989f4ffdaa0b6, 9588850bfa75c78ce73c2f6f72544d19d2e9beb6, 36c68dc909845c049e0286d229bc502947239452, 97fcd34aa9fd73cefe3120ac9a82ca9d7763922f |
| Linux/Linuxgeneric | 3.7 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: btrfs: abort transaction on failure to update inode for hole punching and reflinking If we fail to update the inode we error out without aborting the transaction, which can result in a persistent inconsistency if after the failure the transaction is committed, as we have dropped file extent items from a range and either punched a hole or insert a new file extent item for that range (for reflinks). So add the missing transaction abort.
Quoted source text, attributed separately from HOL analysis.