Description
In the Linux kernel, the following vulnerability has been resolved:

btrfs: retry verity reads for not-uptodate Merkle folios

btrfs_read_merkle_tree_page() can find a folio in the mapping that is not
uptodate. After taking the folio lock, the current code treats that state
as a read error and returns -EIO.

That can make a previous transient read failure sticky. If the failed read
left a not-uptodate folio in the mapping, later callers find that folio and
fail instead of retrying the read.

Keep the existing page-cache insertion and locking order, but retry the
Merkle item read when a not-uptodate folio is found in the mapping. Also
unlock the folio when read_key_bytes() fails so that a later caller can
lock it and retry the read.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via persistent read errors on btrfs
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the btrfs implementation of the Linux kernel. When reading merkle tree pages, the code can find a folio in the mapping that is not marked as up-to-date. The current logic treats that state as a permanent read error and returns -EIO. This means that a transient read failure can become sticky: if a failed read leaves a not‑up‑to‑date folio in the mapping, subsequent callers will encounter the same folio and fail again, preventing the system from recovering by retrying the read. As a result, files or metadata can become inaccessible, potentially leading to data loss or denial of service. The bug does not involve code execution but introduces a significant reliability issue. An attacker who can repeatedly trigger read errors on btrfs data or metadata could cause persistent failure of file access. The weakness is an improper handling of error conditions, leading to denial of service. The vulnerability is fixed by adjusting the read logic to retry merkle item reads when a not‑up‑date folio is encountered and by unlocking the folio on read_key_bytes() failure to allow later retries.

Affected Systems

The issue affects any Linux kernel using the btrfs filesystem that includes the vulnerable module. The vendor list includes Linux:Linux, meaning all community and distribution kernels built with btrfs support. No specific version ranges are listed, so all builds prior to the patch commit are potentially affected.

Risk and Exploitability

The CVSS details are not provided, but the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The attack vector is inferred to be local: a user with read‑access to a btrfs filesystem can trigger the error condition by manipulating file reads. The impact is confined to the affected filesystem; it does not provide remote code execution. Given the low EPSS and lack of external exploitation reports, the immediate risk is moderate if the affected kernel is in use, but can be mitigated by applying the patch promptly.

Generated by OpenCVE AI on September 19, 2026 at 03:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that implements the btrfs_merkle_tree_page retry logic and unlocks the folio on error.
  • For systems that cannot be patched immediately, schedule a kernel upgrade to a version that includes the fix and verify that btrfs management tools (e.g., btrfs check) report no persistent read errors.
  • Enable btrfs integrity checks and monitor system logs for repeated –EIO errors on read operations. If persistent errors are observed, schedule maintenance to address the underlying storage issue and confirm kernel update.

Generated by OpenCVE AI on September 19, 2026 at 03:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: btrfs: retry verity reads for not-uptodate Merkle folios btrfs_read_merkle_tree_page() can find a folio in the mapping that is not uptodate. After taking the folio lock, the current code treats that state as a read error and returns -EIO. That can make a previous transient read failure sticky. If the failed read left a not-uptodate folio in the mapping, later callers find that folio and fail instead of retrying the read. Keep the existing page-cache insertion and locking order, but retry the Merkle item read when a not-uptodate folio is found in the mapping. Also unlock the folio when read_key_bytes() fails so that a later caller can lock it and retry the read.
Title btrfs: retry verity reads for not-uptodate Merkle folios
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:59.435Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:22.640

Modified: 2026-09-17T17:17:22.640

Link: CVE-2026-90262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T10:00:07Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition