Junglewise Threat Intelligence

CVE-2026-43338: Linux Kernel Btrfs transaction abort in qgroup ioctls

CVE-2026-43338 · Severity: medium · CVSS 5.5 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Btrfs file system component. The issue occurs when managing disk quotas (qgroups), where the system fails to reserve enough internal space for tracking changes. This can lead to a system crash or a 'transaction abort,' potentially causing service interruptions or data availability issues on affected Linux servers.

Technical details

A vulnerability in the Btrfs implementation within the Linux kernel arises from qgroup ioctls (assign, create, limit) using 'btrfs_join_transaction' instead of 'btrfs_start_transaction'. Because joining a transaction does not reserve space for quota tree updates or delayed references, the system may exhaust the global block reserve under heavy quota management operations. This leads to an -ENOSPC (No space left on device) error during metadata updates, triggering a transaction abort and a kernel warning. Attackers with local access could potentially trigger this condition to cause a Denial of Service (DoS). The fix involves updating the ioctl handlers to use 'btrfs_start_transaction' with explicit item counts to ensure proper space reservation.

Affected products

  • Linux Linux Kernel 6.19.0-rc8-btrfs-next-225+

Timeline

  • 2026-02-13: other: Patch authored
  • 2026-04-11: patched: Patch committed to stable tree
  • 2026-05-08: advisory: CVE published

References

Related threats