---
id: CVE-2026-90259
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()

  In that function, we round down the start position and round up the
  ending position.

  But …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()

  In that function, we round down the start position and round up the
  ending position.

  But …
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= bc42bda22345efdb5d8b578d1b4df2c6eaa85c58 <
    e6edde29990af8064b9d12217ec03db231ccd55d
  - >-
    Linux >= bc42bda22345efdb5d8b578d1b4df2c6eaa85c58 <
    c4c136555ff90f1e2921cc42da43daac0ef9985e
  - >-
    Linux >= bc42bda22345efdb5d8b578d1b4df2c6eaa85c58 <
    9102b179512e11644fb0489ae62010a09afa199c
  - Linux 4.13
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:22.330'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90259'
references:
  - url: 'https://git.kernel.org/stable/c/9102b179512e11644fb0489ae62010a09afa199c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c4c136555ff90f1e2921cc42da43daac0ef9985e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e6edde29990af8064b9d12217ec03db231ccd55d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.841Z'
epss: 0.00206
epssPercentile: 0.09429
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()

In that function, we round down the start position and round up the
ending position.

But during the calculation of @len, we use "round_up(start + len,
sectorsize)", which is the rounded up end position, not the rounded up
length.

Which results a much larger length, and later we are still using
"start + len", which is completely incorrect.

Fix it by declaring a local @aligned_start and @aligned_len and use them
instead.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
