Description
In the Linux kernel, the following vulnerability has been resolved:

btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()

In that function, we round down the start position and round up the
ending position.

But during the calculation of @len, we use "round_up(start + len,
sectorsize)", which is the rounded up end position, not the rounded up
length.

Which results a much larger length, and later we are still using
"start + len", which is completely incorrect.

Fix it by declaring a local @aligned_start and @aligned_len and use them
instead.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption
Action: Patch immediately
AI Analysis

Impact

A calculation error in the Btrfs subsystem’s qgroup_free_reserved_data function incorrectly rounds up the end position, which results in an overestimation of the length used later in the code. This miscalculation can corrupt kernel memory, potentially allowing an attacker to execute arbitrary code or trigger a denial‑of‑service by crashing the system.

Affected Systems

The vulnerability affects the Linux kernel’s Btrfs implementation, specifically the qgroup module. No specific kernel release numbers are listed in the advisory; however, the fix is included in the referenced commit series and should be present in later kernel releases.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation probability. Nevertheless, kernel memory corruption is a highly severe issue; an attacker would typically need local access or a method to trigger the vulnerable path. No public exploits have been reported at this time.

Generated by OpenCVE AI on September 19, 2026 at 04:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the qgroup_free_reserved_data fix (e.g., a kernel incorporating the referenced commits).
  • If an immediate kernel upgrade is not possible, backport the relevant commit to your current kernel tree.
  • If you are using a distribution that packages the kernel, check with the vendor for a recommended update or patch release that includes the fix.

Generated by OpenCVE AI on September 19, 2026 at 04:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-190

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data() In that function, we round down the start position and round up the ending position. But during the calculation of @len, we use "round_up(start + len, sectorsize)", which is the rounded up end position, not the rounded up length. Which results a much larger length, and later we are still using "start + len", which is completely incorrect. Fix it by declaring a local @aligned_start and @aligned_len and use them instead.
Title btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:57.416Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90259

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:22.330

Modified: 2026-09-17T17:17:22.330

Link: CVE-2026-90259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T08:30:16Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-190

    Integer Overflow or Wraparound