Description
In the Linux kernel, the following vulnerability has been resolved:

btrfs: zoned: don't clobber the extent buffer when zeroing it out

On a zoned filesystem a freed-but-still-dirty tree block is written out
as zeros (EXTENT_BUFFER_ZONED_ZEROOUT) only to keep the zone write
pointer advancing. btree_csum_one_bio() implemented this by memzeroing
the extent buffer's own folios before submission.

That destroys the in-memory buffer while it may still be referenced. In
particular btrfs_free_tree_block() can run on it afterwards and reads
the header to add a delayed reference; once the header has been zeroed
it frees bytenr 0 and corrupts the extent tree (the
btrfs_header_bytenr(buf) != 0 ASSERT in btrfs_free_tree_block(), or an
"unable to find ref" abort). It is flaky and reproduces under fsstress,
e.g. generic/461 and generic/013.

Write the zeros to disk from the shared zero page instead and leave the
extent buffer content untouched, so any later reference - including the
delayed reference from btrfs_free_tree_block() - still sees a valid
header. end_bbio_meta_write() now clears writeback on the buffer's own
folios, as the bio no longer carries them.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Filesystem corruption and service disruption
Action: Update kernel
AI Analysis

Impact

In the Linux kernel, a defect in the BTRFS implementation for zoned storage causes the extent buffer to be cleared with a memzero operation while freeing a tree block. Because the buffer may still be referenced by cleanup code, the in‑memory header is destroyed. The subsequent call to btrfs_free_tree_block reads the zeroed header, corrupting the extent tree or triggering an assertion and aborting the kernel. The result is a kernel panic or corruption of the BTRFS filesystem, potentially leading to data loss or a denial of service.

Affected Systems

All Linux kernel releases that include unpatched BTRFS zoned code and are configured with zoned support are vulnerable. The vulnerability applies to any system using BTRFS on a zoned storage device, but specific version or distribution information is not provided.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating high severity. The EPSS score of less than 1 % shows a low likelihood of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. It does not provide direct code execution; instead, it can lead to kernel crashes and filesystem corruption when the patched BTRFS zoned path is executed during normal operation.

Generated by OpenCVE AI on September 20, 2026 at 01:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a Linux kernel update that includes the BTRFS zoned patch which writes zeros to a shared zero page instead of clearing the extent buffer.
  • If an update is not immediately possible, consider disabling zoned support by flattening or shrinking the BTRFS volume, removing the problematic code path.
  • Monitor kernel logs for BTRFS assertions or crashes and back up data regularly to mitigate potential loss.

Generated by OpenCVE AI on September 20, 2026 at 01:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: don't clobber the extent buffer when zeroing it out On a zoned filesystem a freed-but-still-dirty tree block is written out as zeros (EXTENT_BUFFER_ZONED_ZEROOUT) only to keep the zone write pointer advancing. btree_csum_one_bio() implemented this by memzeroing the extent buffer's own folios before submission. That destroys the in-memory buffer while it may still be referenced. In particular btrfs_free_tree_block() can run on it afterwards and reads the header to add a delayed reference; once the header has been zeroed it frees bytenr 0 and corrupts the extent tree (the btrfs_header_bytenr(buf) != 0 ASSERT in btrfs_free_tree_block(), or an "unable to find ref" abort). It is flaky and reproduces under fsstress, e.g. generic/461 and generic/013. Write the zeros to disk from the shared zero page instead and leave the extent buffer content untouched, so any later reference - including the delayed reference from btrfs_free_tree_block() - still sees a valid header. end_bbio_meta_write() now clears writeback on the buffer's own folios, as the bio no longer carries them.
Title btrfs: zoned: don't clobber the extent buffer when zeroing it out
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:54:13.818Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90260

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:22.433

Modified: 2026-09-18T18:17:51.297

Link: CVE-2026-90260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:15:07Z

Weaknesses