๐Ÿ” CVE Alert

CVE-2026-46164

HIGH 7.0

btrfs: fix double free in create_space_info_sub_group() error path

CVSS Score
7.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free in create_space_info_sub_group() error path When kobject_init_and_add() fails, the call chain is: create_space_info_sub_group() -> btrfs_sysfs_add_space_info_type() -> kobject_init_and_add() -> failure -> kobject_put(&sub_group->kobj) -> space_info_release() -> kfree(sub_group) Then control returns to create_space_info_sub_group(), where: btrfs_sysfs_add_space_info_type() returns error -> kfree(sub_group) Thus, sub_group is freed twice. Keep parent->sub_group[index] = NULL for the failure path, but after btrfs_sysfs_add_space_info_type() has called kobject_put(), let the kobject release callback handle the cleanup.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 28, 2026
Last Updated May 30, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
0bd151ce4200ca847990e05cca29a76456982ca5 < d2a675f2e238ec96c8e91e2718c1f910c9c8fb21 190d5a7c4fe42b8c9aa46e3336389e7cb10395bb < 14b22be1dd844383eb03af9b1ee3b6b25d32aeaf f92ee31e031c7819126d2febdda0c3e91f5d2eb9 < dfd05a16b5c9d1d98b47905f37f2fccda52173d1 f92ee31e031c7819126d2febdda0c3e91f5d2eb9 < 259af6857a1b4f1e9ef8b780353f9d11c26a22bd f92ee31e031c7819126d2febdda0c3e91f5d2eb9 < a7449edf96143f192606ec8647e3167e1ecbd728 64c7ddda83acfbaa0efb381a1928ce908c584607 6.6.122 < 6.6.141 6.12.67 < 6.12.90 6.1.162 < 6.2
Linux / Linux
6.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/d2a675f2e238ec96c8e91e2718c1f910c9c8fb21 git.kernel.org: https://git.kernel.org/stable/c/14b22be1dd844383eb03af9b1ee3b6b25d32aeaf git.kernel.org: https://git.kernel.org/stable/c/dfd05a16b5c9d1d98b47905f37f2fccda52173d1 git.kernel.org: https://git.kernel.org/stable/c/259af6857a1b4f1e9ef8b780353f9d11c26a22bd git.kernel.org: https://git.kernel.org/stable/c/a7449edf96143f192606ec8647e3167e1ecbd728