PT-2026-94608 · Linux · Linux Kernel
CVE-2026-90260
·
Published
2026-09-17
·
Updated
2026-09-24
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the btrfs zoned filesystem where a freed-but-still-dirty tree block is written as zeros to maintain the zone write pointer. The
btree csum one bio() function previously performed this by zeroing the extent buffer's own folios before submission, which destroyed the in-memory buffer while it might still be referenced. Consequently, if btrfs free tree block() runs afterward, it reads a zeroed header, leading to the corruption of the extent tree or a system abort.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel