Description
In the Linux kernel, the following vulnerability has been resolved:

btrfs: zoned: flush active metadata block group at btree_writepages() start

btree_writepages() writes the btree inode's dirty metadata in ascending
logical address order. On a zoned filesystem only one metadata and one
system block group is active for writing at a time, and
check_bg_is_active() (via btrfs_check_meta_write_pointer()) pivots the
active block group as writeback moves from one block group to the next.

If the active block group sits at a higher logical address than another
block group that also holds dirty metadata, the ascending walk reaches
the lower one first and, to write it, has to finish the active block
group and activate the lower one. It cannot finish a block group that
still has unsent IO, and during WB_SYNC_ALL && !for_sync (commit)
writeback it deliberately refuses to wait for that IO under
fs_info->zoned_meta_io_lock, as that can deadlock. The pivot thus cannot
issue the submission itself either, so it gives up:
btrfs_check_meta_write_pointer() returns -EAGAIN, which
btrfs_write_and_wait_transaction() treats as fatal and aborts the
transaction, forcing the filesystem read-only. This happens
intermittently under metadata-heavy relocation (e.g. fstests btrfs/187).

Flush the active metadata and system block groups at the start of
btree_writepages(), under the fs_info->zoned_meta_io_lock it already
holds, so they have no unsent IO left and the later pivot can finish
them and make forward progress.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (filesystem becomes read‑only)
Action: Apply Patch
AI Analysis

Impact

The Linux kernel btrfs subsystem contains a flaw that can cause the filesystem to be set to read‑only when the kernel attempts to write back metadata on a zoned btrfs device. During a writeback sweep, the active metadata block group may need to be swapped in order to continue. If that block group still has pending I/O, the kernel refuses to wait for completion to avoid a possible deadlock. The resulting error causes the write transaction to abort, propagating a fatal state that forces the filesystem into read‑only mode. The impact is a loss of write capability and service interruption, but there is no direct path to arbitrary code execution or data exfiltration. The weakness is consistent with a synchronization or resource‑management error.

Affected Systems

Affected systems are Linux kernel users running a btrfs filesystem configured for the zoned storage feature. The issue applies to any kernel version that contains the unpatched btrfs code; particular commits identified in the advisory (e2de2989 and ecc05eda9) indicate a wide range of releases. No specific kernel versions are listed in the advisory, so if a system uses the zoned option, it is potentially impacted until a patch is applied.

Risk and Exploitability

The executive summary notes an EPSS score of less than 1%, indicating a very low likelihood of exploitation under normal conditions. The vulnerability is not listed in CISA’s KEV catalog, further suggesting limited known exploitation. Attack vectors are inferred to be local or privileged: the flaw is triggered during internal filesystem writeback, which typically requires kernel memory access and thus is unlikely to be exploitable by remote users. Nonetheless, the denial-of-service nature makes any exploitation objective valuable to an attacker with local or elevated access.

Generated by OpenCVE AI on September 19, 2026 at 03:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the btrfs zoned metadata fix referenced in the advisory (commits e2de2989 and ecc05eda9).
  • If upgrading immediately is not possible, remount the affected btrfs volumes as read‑only to prevent further write attempts until the patch can be applied and the filesystem is checked.
  • Verify the integrity of the filesystem after the patch by running "btrfs check" or a similar filesystem integrity check, and monitor for signs of unexpected read‑only transitions.

Generated by OpenCVE AI on September 19, 2026 at 03:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: flush active metadata block group at btree_writepages() start btree_writepages() writes the btree inode's dirty metadata in ascending logical address order. On a zoned filesystem only one metadata and one system block group is active for writing at a time, and check_bg_is_active() (via btrfs_check_meta_write_pointer()) pivots the active block group as writeback moves from one block group to the next. If the active block group sits at a higher logical address than another block group that also holds dirty metadata, the ascending walk reaches the lower one first and, to write it, has to finish the active block group and activate the lower one. It cannot finish a block group that still has unsent IO, and during WB_SYNC_ALL && !for_sync (commit) writeback it deliberately refuses to wait for that IO under fs_info->zoned_meta_io_lock, as that can deadlock. The pivot thus cannot issue the submission itself either, so it gives up: btrfs_check_meta_write_pointer() returns -EAGAIN, which btrfs_write_and_wait_transaction() treats as fatal and aborts the transaction, forcing the filesystem read-only. This happens intermittently under metadata-heavy relocation (e.g. fstests btrfs/187). Flush the active metadata and system block groups at the start of btree_writepages(), under the fs_info->zoned_meta_io_lock it already holds, so they have no unsent IO left and the later pivot can finish them and make forward progress.
Title btrfs: zoned: flush active metadata block group at btree_writepages() start
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:58.806Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90261

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:22.537

Modified: 2026-09-17T17:17:22.537

Link: CVE-2026-90261

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T04:15:13Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')