CVE-2026-68450
Detail
Received
This CVE record has recently been published to the CVE List and has been included within the NVD dataset.
Description
In the Linux kernel, the following vulnerability has been resolved:
btrfs: free mapping node on duplicate reloc root insert
__add_reloc_root() allocates a mapping_node before inserting it into
rc->reloc_root_tree. If rb_simple_insert() finds an existing entry, it
returns the existing rb_node and leaves the newly allocated node unlinked.
The error path then returns -EEXIST without freeing the new node. Since
the node was never inserted into reloc_root_tree, the later cleanup in
put_reloc_control() cannot find it either.
Free the newly allocated node before returning -EEXIST.
The callers currently assert that -EEXIST should not happen, so this is a
defensive cleanup for an unexpected duplicate insert path. If the path is
ever reached, the local allocation should still be released.
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 2.0 Severity and Vector Strings:
NVD assessment
not yet provided.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
Change History
3 change records found show changes
CVE Modified by kernel.org
8/19/2026 1:20:50 PM
Action
Type
Old Value
New Value
Added
Reference
https://git.kernel.org/stable/c/29d9746812d8b7c37d594f484e994fd552c3ec33
Added
Reference
https://git.kernel.org/stable/c/b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8
Changed
Affected
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"92bedc0455552b42ada1a1f42b0e3a8593cdfccc","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"14a8be9428435ee17f17fae7991215c246b7fd43","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"797dc567146c7e3c4f8d9680e4fbc76e0a6d9151","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"ae0629ff9ccb836416ada129f4edc7efea6eaaad","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"6a8269b6459ed870a8156c106a0f597383907872","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
Record truncated, showing 2048 of 2211 characters.
View Entire Change Record
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"29d9746812d8b7c37d594f484e994fd552c3ec33","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"b7c5b8e1d5f0779dfbabc3068b7ac0f12e53b3a8","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"92bedc0455552b42ada1a1f42b0e3a8593cdfccc","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"14a8be9428435ee17f17fae7991215c246b7fd43","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"797dc567146c7e3c4f8d9680e4fbc76e0a6d9151","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"ae0629ff9ccb836416ada129f4edc7efea6eaaad","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"6a8269b6459ed870a8156c106a0f597383907872","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"5.15.216","lessThanOrEqual":"5.15.*","versionType":"semver","status":"unaffected"},{"version":"6.1.183","lessThanOrEqual":"6.1.*","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEq
CVE Modified by kernel.org
8/17/2026 2:17:54 AM
Action
Type
Old Value
New Value
Changed
Affected
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"92bedc0455552b42ada1a1f42b0e3a8593cdfccc","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"14a8be9428435ee17f17fae7991215c246b7fd43","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"797dc567146c7e3c4f8d9680e4fbc76e0a6d9151","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"ae0629ff9ccb836416ada129f4edc7efea6eaaad","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"6a8269b6459ed870a8156c106a0f597383907872","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"92bedc0455552b42ada1a1f42b0e3a8593cdfccc","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"14a8be9428435ee17f17fae7991215c246b7fd43","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"797dc567146c7e3c4f8d9680e4fbc76e0a6d9151","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"ae0629ff9ccb836416ada129f4edc7efea6eaaad","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"6a8269b6459ed870a8156c106a0f597383907872","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
New CVE Received from kernel.org
8/11/2026 9:17:07 PM
Action
Type
Old Value
New Value
Added
Description
In the Linux kernel, the following vulnerability has been resolved:
btrfs: free mapping node on duplicate reloc root insert
__add_reloc_root() allocates a mapping_node before inserting it into
rc->reloc_root_tree. If rb_simple_insert() finds an existing entry, it
returns the existing rb_node and leaves the newly allocated node unlinked.
The error path then returns -EEXIST without freeing the new node. Since
the node was never inserted into reloc_root_tree, the later cleanup in
put_reloc_control() cannot find it either.
Free the newly allocated node before returning -EEXIST.
The callers currently assert that -EEXIST should not happen, so this is a
defensive cleanup for an unexpected duplicate insert path. If the path is
ever reached, the local allocation should still be released.
Added
Reference
https://git.kernel.org/stable/c/14a8be9428435ee17f17fae7991215c246b7fd43
Added
Reference
https://git.kernel.org/stable/c/6a8269b6459ed870a8156c106a0f597383907872
Added
Reference
https://git.kernel.org/stable/c/797dc567146c7e3c4f8d9680e4fbc76e0a6d9151
Added
Reference
https://git.kernel.org/stable/c/92bedc0455552b42ada1a1f42b0e3a8593cdfccc
Added
Reference
https://git.kernel.org/stable/c/ae0629ff9ccb836416ada129f4edc7efea6eaaad
Added
Affected
[{"vendor":"Linux","product":"Linux","defaultStatus":"unaffected","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"92bedc0455552b42ada1a1f42b0e3a8593cdfccc","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"14a8be9428435ee17f17fae7991215c246b7fd43","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"797dc567146c7e3c4f8d9680e4fbc76e0a6d9151","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"ae0629ff9ccb836416ada129f4edc7efea6eaaad","versionType":"git","status":"affected"},{"version":"57a304cfd43b2b4a5b44b8f5dc026abb34183068","lessThan":"6a8269b6459ed870a8156c106a0f597383907872","versionType":"git","status":"affected"}]},{"vendor":"Linux","product":"Linux","defaultStatus":"affected","programFiles":["fs/btrfs/relocation.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","versions":[{"version":"5.13","status":"affected"},{"version":"0","lessThan":"5.13","versionType":"semver","status":"unaffected"},{"version":"6.6.148","lessThanOrEqual":"6.6.*","versionType":"semver","status":"unaffected"},{"version":"6.12.101","lessThanOrEqual":"6.12.*","versionType":"semver","status":"unaffected"},{"version":"6.18.42","lessThanOrEqual":"6.18.*","versionType":"semver","status":"unaffected"},{"version":"7.1.6","lessThanOrEqual":"7.1.*","versionType":"semver","status":"unaffected"},{"version":"7.2-rc5","lessThanOrEqual":"*","versionType":"original_commit_for_fix","status":"unaffected"}]}]
Quick Info
CVE Dictionary Entry: CVE-2026-68450 NVD
Published Date: 08/11/2026 NVD
Last Modified: 08/19/2026
Source: kernel.org