---
id: CVE-2026-90261
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  btrfs: zoned: flush active metadata block group at btree_writepages() start

  btree_writepages() writes the btree inode's dirty metadata in ascending
  logical address ord…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  btrfs: zoned: flush active metadata block group at btree_writepages() start

  btree_writepages() writes the btree inode's dirty metadata in ascending
  logical address ord…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 13bb483d32abb6f8ebd40141d87eb68f11cc2dd2 <
    e2de2989adb3e58c2320e57c255f52e065667b5e
  - >-
    Linux >= 13bb483d32abb6f8ebd40141d87eb68f11cc2dd2 <
    ecc05eda9a346848ae01a6c8bfa3f0bec133bd8b
  - Linux fca3a1cd3ba47f1815e0c0fcdc9aafaf02ee0a75
  - Linux >= 6.5.5 < 6.6
  - Linux 6.6
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:22.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90261'
references:
  - url: 'https://git.kernel.org/stable/c/e2de2989adb3e58c2320e57c255f52e065667b5e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ecc05eda9a346848ae01a6c8bfa3f0bec133bd8b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.841Z'
epss: 0.0021
epssPercentile: 0.11527
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

btrfs: zoned: flush active metadata block group at btree_writepages() start

btree_writepages() writes the btree inode's dirty metadata in ascending
logical address order. On a zoned filesystem only one metadata and one
system block group is active for writing at a time, and
check_bg_is_active() (via btrfs_check_meta_write_pointer()) pivots the
active block group as writeback moves from one block group to the next.

If the active block group sits at a higher logical address than another
block group that also holds dirty metadata, the ascending walk reaches
the lower one first and, to write it, has to finish the active block
group and activate the lower one. It cannot finish a block group that
still has unsent IO, and during WB_SYNC_ALL && !for_sync (commit)
writeback it deliberately refuses to wait for that IO under
fs_info->zoned_meta_io_lock, as that can deadlock. The pivot thus cannot
issue the submission itself either, so it gives up:
btrfs_check_meta_write_pointer() returns -EAGAIN, which
btrfs_write_and_wait_transaction() treats as fatal and aborts the
transaction, forcing the filesystem read-only. This happens
intermittently under metadata-heavy relocation (e.g. fstests btrfs/187).

Flush the active metadata and system block groups at the start of
btree_writepages(), under the fs_info->zoned_meta_io_lock it already
holds, so they have no unsent IO left and the later pivot can finish
them and make forward progress.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
