---
id: CVE-2026-90260
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  btrfs: zoned: don't clobber the extent buffer when zeroing it out

  On a zoned filesystem a freed-but-still-dirty tree block is written out
  as zeros (EXTENT_BUFFER_ZONED…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  btrfs: zoned: don't clobber the extent buffer when zeroing it out

  On a zoned filesystem a freed-but-still-dirty tree block is written out
  as zeros (EXTENT_BUFFER_ZONED…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= aa6313e6ff2bfbf736a2739047bba355d8241584 <
    92484ad014f2e2b0e0e7bbc1610951e978cf557c
  - >-
    Linux >= aa6313e6ff2bfbf736a2739047bba355d8241584 <
    98e3747587f9f87f010d8d7e55786216249a94af
  - >-
    Linux >= aa6313e6ff2bfbf736a2739047bba355d8241584 <
    db4b9eefc8ee0bcaeee4d5e6a7313905f6a2fe7c
  - Linux 6.8
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:51.297'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90260'
references:
  - url: 'https://git.kernel.org/stable/c/92484ad014f2e2b0e0e7bbc1610951e978cf557c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/98e3747587f9f87f010d8d7e55786216249a94af'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/db4b9eefc8ee0bcaeee4d5e6a7313905f6a2fe7c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00157
epssPercentile: 0.05312
ingestedAt: '2026-09-17T16:21:47.842Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

btrfs: zoned: don't clobber the extent buffer when zeroing it out

On a zoned filesystem a freed-but-still-dirty tree block is written out
as zeros (EXTENT_BUFFER_ZONED_ZEROOUT) only to keep the zone write
pointer advancing. btree_csum_one_bio() implemented this by memzeroing
the extent buffer's own folios before submission.

That destroys the in-memory buffer while it may still be referenced. In
particular btrfs_free_tree_block() can run on it afterwards and reads
the header to add a delayed reference; once the header has been zeroed
it frees bytenr 0 and corrupts the extent tree (the
btrfs_header_bytenr(buf) != 0 ASSERT in btrfs_free_tree_block(), or an
"unable to find ref" abort). It is flaky and reproduces under fsstress,
e.g. generic/461 and generic/013.

Write the zeros to disk from the shared zero page instead and leave the
extent buffer content untouched, so any later reference - including the
delayed reference from btrfs_free_tree_block() - still sees a valid
header. end_bbio_meta_write() now clears writeback on the buffer's own
folios, as the bio no longer carries them.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
