PT-2026-94608 · Linux · Linux Kernel

CVE-2026-90260

·

Published

2026-09-17

·

Updated

2026-09-24

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the btrfs zoned filesystem where a freed-but-still-dirty tree block is written as zeros to maintain the zone write pointer. The btree csum one bio() function previously performed this by zeroing the extent buffer's own folios before submission, which destroyed the in-memory buffer while it might still be referenced. Consequently, if btrfs free tree block() runs afterward, it reads a zeroed header, leading to the corruption of the extent tree or a system abort.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-90260
OPENSUSE-SU-2026:11880-1

Affected Products

Linux Kernel