CVE-2026-93255

UNRATEDCVSS · not yet scoredTrending — 3 sources updated this week
—
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: 0.2%CVSS v2: —Exploit: None knownExposed services: Not assessed

No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.

In the Linux kernel, the following vulnerability has been resolved:

btrfs: make sure EXTENT_BUFFER_READING is cleared under refs_lock

[FALSE ALERTS] There is a bug report that the warning inside invalidate_and_check_btree_folios() got triggered during btrfs/298:

BTRFS info (device sdd): first mount of filesystem f9bf732a-a19b-44b9-99a7-614ddff168e2 BTRFS info (device sdd): using crc32c checksum algorithm BTRFS error (device sdd): failed to find fsid cb2fdb42-b638-4f2f-badd-4127467ba674 when attempting to open seed devices BTRFS error (device sdd): failed to read chunk tree: -2 ------------[ cut here ]------------ WARNING: disk-io.c:3342 at invalidate_and_check_btree_folios+0x260/0x3c0 [btrfs], CPU#4: mount/125993 CPU: 4 UID: 0 PID: 125993 Comm: mount Tainted: G W OE 7.1.0-rc7-custom+ #1 PREEMPT(full) Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20250812-19.fc42 08/12/2025 Call trace: invalidate_and_check_btree_folios+0x260/0x3c0 [btrfs] (P) open_ctree+0x1f50/0x23b0 [btrfs] btrfs_get_tree+0x89c/0xc48 [btrfs] vfs_get_tree+0x30/0x110 vfs_cmd_create+0x58/0xe8 __arm64_sys_fsconfig+0x39c/0x518 invoke_syscall.constprop.0+0x48/0x120 el0_svc_common.constprop.0+0x40/0xe8 do_el0_svc+0x24/0x38 el0_svc+0x50/0x310 el0t_64_sync_handler+0xa0/0xe8 el0t_64_sync+0x198/0x1a0 ---[ end trace 0000000000000000 ]--- BTRFS warning (device sdd): unable to release extent buffer 365985792 owner 3 gen 17 refs 3 flags 0x5

[CAUSE] In that invalidate_and_check_btree_folios() we wait for the eb to finish its read, then check if it's only held by us and the btree inode.

If not, then do a warning as it may be still held, and could cause problems.

But there is a small window where the check can lead to false alerts:

Thread A (Read endio) | Thread B (Unmount) ----------------------------------+------------------------------------- end_bbio_meta_read() | | The eb has one extra ref held | | by the reader, and has | | EXTENT_BUFFER_READING flag set | invalidate_and_check_btree_folios() | | | |- clear_extent_buffer_reading() | | | | |- wait_on_bit_io(); | | | The EXTENT_BUFFER_READING flag is | | | cleared | | |- if (refcount_read(eb->refs) > 2) | | The eb is held by the read, us | | and btree inode, thus it | | will trigger the warning |- free_extent_buffer() |

[FIX] Introduce a helper, free_extent_buffer_clear_reading().

If the new parameter, @clear_reading, is set, we will hold the spinlock at the beginning of free_extent_buffer_clear_reading() to make sure the EXTENT_BUFFER_READING flag is cleared inside the same critical section of decreasing refs.

Now free_extent_buffer() will just call free_extent_buffer_clear_reading() with @clear_reading set to false, so no behavior change.

But for end_bbio_meta_read(), it will not clear_extent_buffer_reading() directly, but pass @clear_reading as true.

Then inside invalidate_and_check_btree_folios(), hold the refs_lock before reading refs. So that we eliminate the race window completely.

CVSS v3
—
EchelonGraph score
Not yet assessedNo source has published severity data for this CVE yet — no CVSS score from NVD or a CNA, no GitHub advisory, and it is not in CISA KEV. This is not a rating of zero; we cannot assess it yet.
EG Score
—
EG Risk
—
EPSS PROB
0.2%
EPSS %ILE
7th
KEV
Not listed

Published

September 24, 2026

Last Modified

September 24, 2026

Vendor Advisories for CVE-2026-93255(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Affected Packages

(1 across 1 ecosystem)
Debian:14(1)
PackageVulnerable rangeFix by version rangeDependents
linux6.12.100-1 ... 7.2~rc7-1~exp1 (176 versions)
  • every version up to 7.2.6-1: fixed in 7.2.6-1
—

Data Freshness Timeline

(refreshed 8× in last 7d / 15× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-10-04 23:22 UTCEPSS rescore
  2. 2026-10-04 11:32 UTCGHSA enrichment
  3. 2026-10-01 19:51 UTCEPSS rescore
  4. 2026-10-01 05:12 UTCEG score recompute
  5. 2026-10-01 05:12 UTCGHSA enrichment
  6. 2026-09-30 15:04 UTCEPSS rescore
  7. 2026-09-28 13:52 UTCEPSS rescore
  8. 2026-09-28 13:52 UTCEPSS rescore
  9. 2026-09-27 22:53 UTCEG score recompute
  10. 2026-09-27 22:53 UTCGHSA enrichment
  11. 2026-09-27 13:49 UTCEPSS rescore
  12. 2026-09-26 15:59 UTCEPSS rescore
  13. 2026-09-24 16:30 UTCNVD update
  14. 2026-09-24 15:57 UTCEG score recompute
  15. 2026-09-24 15:56 UTCMITRE cvelistV5first tracked

Frequently asked(4)

What is CVE-2026-93255?
CVE-2026-93255 is a publicly disclosed vulnerability published on September 24, 2026. In the Linux kernel, the following vulnerability has been resolved: btrfs: make sure EXTENTBUFFERREADING is cleared under refs_lock [FALSE ALERTS] There is a bug report that the warning inside invalidateandcheckbtreefolios() got triggered during btrfs/298: BTRFS info (device sdd): first mount of…
When was CVE-2026-93255 disclosed?
CVE-2026-93255 was first published on September 24, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-93255 actively exploited?
CVE-2026-93255 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0.2% probability of exploitation in the next 30 days (7th percentile of EPSS-scored CVEs).
How do I remediate CVE-2026-93255?
No fix for CVE-2026-93255 is confirmed yet. Until one is published, restrict network exposure of the affected system or apply the vendor's mitigation — for example, keep it off the internet or limit it to trusted networks — and watch the vendor's advisory for the fix. The vendor advisories EchelonGraph has for CVE-2026-93255 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-93255

Explore →

Is Your Infrastructure Affected by CVE-2026-93255?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.