{"id":"AZL-104561","summary":"CVE-2026-98081 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: finish active block group cleanup if call_zone_finish() fails\n\ndo_zone_finish() clears BLOCK_GROUP_FLAG_ZONE_IS_ACTIVE before finishing\nthe zones. If call_zone_finish() then fails it returned early, leaving the\nnow inactive block group on fs_info-\u003ezone_active_bgs, leaking its\nreference, the BTRFS_FS_NEED_ZONE_FINISH waiters are never woken, and as\nits alloc_offset equals the zone capacity btrfs_zone_finish_one_bg() keeps\nselecting it, spinning btrfs_zoned_activate_one_bg().\n\nFall through to the cleanup on failure too and return the error, but keep\nthe block group read-only as its zones are left inconsistent.","modified":"2026-09-28T05:39:54Z","published":"2026-09-25T11:17:37Z","upstream":["CVE-2026-98081"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98081"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104561.json"}}],"schema_version":"1.9.0"}