Description
In the Linux kernel, the following vulnerability has been resolved:

btrfs: zoned: don't force read-only on transient -EAGAIN from reloc merge

On a zoned FS, btrfs_delayed_refs_rsv_refill() returns -EAGAIN whenever
the over-committed metadata plus the zone_unusable bytes exceeds the
usable size in a metadata block-group to avoid heavy over-commit of
metadata and early ENOSPC in one transaction.

If this happens while doing reclaim, the transaction is getting aborted.

Treat -EAGAIN as a soft, retryable condition in case of block-group
reclaim.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Potential data corruption
Action: Patch
AI Analysis

Impact

The Linux kernel’s btrfs file system, when enabled on zoned block devices, incorrectly treated a retryable error code (-EAGAIN) from the block‑group reclaim logic as fatal. This caused btrfs transactions to be aborted, which could leave the file system state inconsistent and potentially corrupt metadata or user data. The defect represents a failure to handle a temporary over‑commit condition properly, leading to loss or corruption of data rather than simply a denial of service.

Affected Systems

All installations of the Linux kernel that execute the pre‑patch btrfs zoned‑storage code are affected. The issue exists in any kernel containing the buggy logic before the patch commit identifiers 8249dfe46337d599e2087b772a2e32ef9f77282b and e549093c11a2fff8430df3dfbdb45eb9811a69a5 are applied. Systems using btrfs on zoned storage devices are the primary targets; other btrfs configurations are not impacted.

Risk and Exploitability

The CVSS score is not provided, but the EPSS score of less than 1% indicates a very low probability of active exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require local access and the ability to trigger a heavy over‑commit condition on a zoned BTRFS filesystem, making the attack surface narrow. Though the impact includes potential loss of data, the overall risk remains low due to the difficulty of exploitation and the lack of public exploits.

Generated by OpenCVE AI on September 19, 2026 at 14:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a version that contains the patch commit 8249dfe46337d599e2087b772a2e32ef9f77282b or e549093c11a2fff8430df3dfbdb45eb9811a69a5, which treats the –EAGAIN as a retryable condition.
  • If a kernel update is not immediately possible, disable zoned mode for btrfs or revert to a non‑zoned configuration to eliminate the vulnerable code path.
  • Continuously monitor kernel logs for btrfs transaction abort messages and verify that no further –EAGAIN errors are treated as fatal.

Generated by OpenCVE AI on September 19, 2026 at 14:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-152

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: don't force read-only on transient -EAGAIN from reloc merge On a zoned FS, btrfs_delayed_refs_rsv_refill() returns -EAGAIN whenever the over-committed metadata plus the zone_unusable bytes exceeds the usable size in a metadata block-group to avoid heavy over-commit of metadata and early ENOSPC in one transaction. If this happens while doing reclaim, the transaction is getting aborted. Treat -EAGAIN as a soft, retryable condition in case of block-group reclaim.
Title btrfs: zoned: don't force read-only on transient -EAGAIN from reloc merge
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:01.995Z

Reserved: 2026-09-11T19:38:34.796Z

Link: CVE-2026-90266

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:23.147

Modified: 2026-09-17T17:17:23.147

Link: CVE-2026-90266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:00:12Z

Weaknesses
  • CWE-152

    Improper Neutralization of Macro Symbols