« Volver al listado

CVE-2026-90259

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()

In that function, we round down the start position and round up the ending position.

But during the calculation of @len, we use "round_up(start + len, sectorsize)", which is the rounded up end position, not the rounded up length.

Which results a much larger length, and later we are still using "start + len", which is completely incorrect.

Fix it by declaring a local @aligned_start and @aligned_len and use them instead.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90259",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "bc42bda22345efdb5d8b578d1b4df2c6eaa85c58",
              "lessThan": "e6edde29990af8064b9d12217ec03db231ccd55d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bc42bda22345efdb5d8b578d1b4df2c6eaa85c58",
              "lessThan": "c4c136555ff90f1e2921cc42da43daac0ef9985e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "bc42bda22345efdb5d8b578d1b4df2c6eaa85c58",
              "lessThan": "9102b179512e11644fb0489ae62010a09afa199c",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/btrfs/qgroup.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/btrfs/qgroup.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:22.330",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/9102b179512e11644fb0489ae62010a09afa199c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c4c136555ff90f1e2921cc42da43daac0ef9985e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e6edde29990af8064b9d12217ec03db231ccd55d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()\n\nIn that function, we round down the start position and round up the\nending position.\n\nBut during the calculation of @len, we use \"round_up(start + len,\nsectorsize)\", which is the rounded up end position, not the rounded up\nlength.\n\nWhich results a much larger length, and later we are still using\n\"start + len\", which is completely incorrect.\n\nFix it by declaring a local @aligned_start and @aligned_len and use them\ninstead."
    }
  ],
  "lastModified": "2026-09-17T17:17:22.330",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}