{"id":"DEBIAN-CVE-2026-46160","details":"In the Linux kernel, the following vulnerability has been resolved:  btrfs: fix missing last_unlink_trans update when removing a directory  When removing a directory we are not updating its last_unlink_trans field, which can result in incorrect fsync behaviour in case some one fsyncs the directory after it was removed because it's holding a file descriptor on it.  Example scenario:     mkdir /mnt/dir1    mkdir /mnt/dir1/dir2    mkdir /mnt/dir3     sync -f /mnt     # Do some change to the directory and fsync it.    chmod 700 /mnt/dir1    xfs_io -c fsync /mnt/dir1     # Move dir2 out of dir1 so that dir1 becomes empty.    mv /mnt/dir1/dir2 /mnt/dir3/     open fd on /mnt/dir1    call rmdir(2) on path \"/mnt/dir1\"    fsync fd     \u003ctrigger power failure\u003e  When attempting to mount the filesystem, the log replay will fail with an -EIO error and dmesg/syslog has the following:     [445771.626482] BTRFS info (device dm-0): first mount of filesystem 0368bbea-6c5e-44b5-b409-09abe496e650    [445771.626486] BTRFS info (device dm-0): using crc32c checksum algorithm    [445771.627912] BTRFS info (device dm-0): start tree-log replay    [445771.628335] page: refcount:2 mapcount:0 mapping:0000000061443ddc index:0x1d00 pfn:0x7072a5    [445771.629453] memcg:ffff89f400351b00    [445771.629892] aops:btree_aops [btrfs] ino:1    [445771.630737] flags: 0x17fffc00000402a(uptodate|lru|private|writeback|node=0|zone=2|lastcpupid=0x1ffff)    [445771.632359] raw: 017fffc00000402a fffff47284d950c8 fffff472907b7c08 ffff89f458e412b8    [445771.633713] raw: 0000000000001d00 ffff89f6c51d1a90 00000002ffffffff ffff89f400351b00    [445771.635029] page dumped because: eb page dump    [445771.635825] BTRFS critical (device dm-0): corrupt leaf: root=5 block=30408704 slot=10 ino=258, invalid nlink: has 2 expect no more than 1 for dir    [445771.638088] BTRFS info (device dm-0): leaf 30408704 gen 10 total ptrs 17 free space 14878 owner 5    [445771.638091] BTRFS info (device dm-0): refs 4 lock_owner 0 current 3581087    [445771.638094] \titem 0 key (256 INODE_ITEM 0) itemoff 16123 itemsize 160    [445771.638097] \t\tinode generation 3 transid 9 size 16 nbytes 16384    [445771.638098] \t\tblock group 0 mode 40755 links 1 uid 0 gid 0    [445771.638100] \t\trdev 0 sequence 2 flags 0x0    [445771.638102] \t\tatime 1775744884.0    [445771.660056] \t\tctime 1775744885.645502983    [445771.660058] \t\tmtime 1775744885.645502983    [445771.660060] \t\totime 1775744884.0    [445771.660062] \titem 1 key (256 INODE_REF 256) itemoff 16111 itemsize 12    [445771.660064] \t\tindex 0 name_len 2    [445771.660066] \titem 2 key (256 DIR_ITEM 1843588421) itemoff 16077 itemsize 34    [445771.660068] \t\tlocation key (259 1 0) type 2    [445771.660070] \t\ttransid 9 data_len 0 name_len 4    [445771.660075] \titem 3 key (256 DIR_ITEM 2363071922) itemoff 16043 itemsize 34    [445771.660076] \t\tlocation key (257 1 0) type 2    [445771.660077] \t\ttransid 9 data_len 0 name_len 4    [445771.660078] \titem 4 key (256 DIR_INDEX 2) itemoff 16009 itemsize 34    [445771.660079] \t\tlocation key (257 1 0) type 2    [445771.660080] \t\ttransid 9 data_len 0 name_len 4    [445771.660081] \titem 5 key (256 DIR_INDEX 3) itemoff 15975 itemsize 34    [445771.660082] \t\tlocation key (259 1 0) type 2    [445771.660083] \t\ttransid 9 data_len 0 name_len 4    [445771.660084] \titem 6 key (257 INODE_ITEM 0) itemoff 15815 itemsize 160    [445771.660086] \t\tinode generation 9 transid 9 size 8 nbytes 0    [445771.660087] \t\tblock group 0 mode 40777 links 1 uid 0 gid 0    [445771.660088] \t\trdev 0 sequence 2 flags 0x0    [445771.660089] \t\tatime 1775744885.641174097    [445771.660090] \t\tctime 1775744885.645502983    [445771.660091] \t\tmtime 1775744885.645502983    [445771.660105] \t\totime 1775744885.641174097    [445771.660106] \titem 7 key (257 INODE_REF 256) itemoff 15801 itemsize 14    [445771.660107] \t\tindex 2 name_len 4    [445771.660108] \titem 8 key (257 DIR_ITEM 2676584006) itemoff 15767 itemsize 34    [445771.660109] \t\tlocation key (2 ---truncated---","modified":"2026-09-01T16:06:46.110308351Z","published":"2026-05-28T10:16:31.647Z","upstream":["CVE-2026-46160"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-46160"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.176-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.147-1","6.1.148-1","6.1.153-1","6.1.158-1","6.1.159-1","6.1.162-1","6.1.164-1","6.1.170-1","6.1.170-2","6.1.170-3","6.1.172-1","6.1.174-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46160.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.94-1"}]}],"versions":["6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1~bpo12+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46160.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.7-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.107-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.10-1","6.16.11-1","6.16.12-1","6.16.12-1~bpo13+1","6.16.12-2","6.16.3-1","6.16.3-1~bpo13+1","6.16.5-1","6.16.6-1","6.16.7-1","6.16.8-1","6.16.9-1","6.16~rc7-1~exp1","6.17.10-1","6.17.11-1","6.17.12-1","6.17.13-1","6.17.13-1~bpo13+1","6.17.2-1~exp1","6.17.5-1~exp1","6.17.6-1","6.17.7-1","6.17.7-2","6.17.8-1","6.17.8-1~bpo13+1","6.17.9-1","6.18.1-1~exp1","6.18.10-1","6.18.12-1","6.18.12-1~bpo13+1","6.18.13-1","6.18.14-1","6.18.15-1","6.18.15-1~bpo13+1","6.18.2-1~exp1","6.18.3-1","6.18.5-1","6.18.5-1~bpo13+1","6.18.8-1","6.18.9-1","6.18.9-1~bpo13+1","6.18~rc4-1~exp1","6.18~rc4-1~exp2","6.18~rc5-1~exp1","6.18~rc6-1~exp1","6.18~rc7-1~exp1","6.19-1~exp1","6.19.10-1","6.19.10-1~bpo13+1","6.19.11-1","6.19.11-1~bpo13+1","6.19.12-1","6.19.13-1","6.19.13-1~bpo13+1","6.19.14-1","6.19.14-1~bpo13+1","6.19.2-1~exp1","6.19.3-1~exp1","6.19.4-1~exp1","6.19.5-1~exp1","6.19.6-1","6.19.6-2","6.19.6-2~bpo13+1","6.19.8-1","6.19.8-1~bpo13+1","6.19~rc4-1~exp1","6.19~rc5-1~exp1","6.19~rc6-1~exp1","6.19~rc7-1~exp1","6.19~rc8-1~exp1","7.0-1~exp1","7.0.1-1~exp1","7.0.3-1","7.0.4-1","7.0.4-1~bpo13+1","7.0.7-1~bpo13+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46160.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}