« Volver al listado

CVE-2026-90262

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

btrfs: retry verity reads for not-uptodate Merkle folios

btrfs_read_merkle_tree_page() can find a folio in the mapping that is not uptodate. After taking the folio lock, the current code treats that state as a read error and returns -EIO.

That can make a previous transient read failure sticky. If the failed read left a not-uptodate folio in the mapping, later callers find that folio and fail instead of retrying the read.

Keep the existing page-cache insertion and locking order, but retry the Merkle item read when a not-uptodate folio is found in the mapping. Also unlock the folio when read_key_bytes() fails so that a later caller can lock it and retry the read.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90262",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "06ed09351b67eb1114ae106a87a0ee3ea9adb3db",
              "lessThan": "90e9eae1b5907fa36620ffb7f4f1a4afa9333427",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06ed09351b67eb1114ae106a87a0ee3ea9adb3db",
              "lessThan": "c1fa005cdf3b7ff14cdfd7d512830088a3fc256b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06ed09351b67eb1114ae106a87a0ee3ea9adb3db",
              "lessThan": "12b6d1a1715cbced2e445ca353f9c9987b8636e2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06ed09351b67eb1114ae106a87a0ee3ea9adb3db",
              "lessThan": "81241f734f0f662378f5ffc53882b012923e6fe5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06ed09351b67eb1114ae106a87a0ee3ea9adb3db",
              "lessThan": "8cc569696dac51fc62bb39b3b8f530582b916d29",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/btrfs/verity.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/btrfs/verity.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:22.640",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/12b6d1a1715cbced2e445ca353f9c9987b8636e2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/81241f734f0f662378f5ffc53882b012923e6fe5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8cc569696dac51fc62bb39b3b8f530582b916d29",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/90e9eae1b5907fa36620ffb7f4f1a4afa9333427",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c1fa005cdf3b7ff14cdfd7d512830088a3fc256b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: retry verity reads for not-uptodate Merkle folios\n\nbtrfs_read_merkle_tree_page() can find a folio in the mapping that is not\nuptodate.  After taking the folio lock, the current code treats that state\nas a read error and returns -EIO.\n\nThat can make a previous transient read failure sticky.  If the failed read\nleft a not-uptodate folio in the mapping, later callers find that folio and\nfail instead of retrying the read.\n\nKeep the existing page-cache insertion and locking order, but retry the\nMerkle item read when a not-uptodate folio is found in the mapping.  Also\nunlock the folio when read_key_bytes() fails so that a later caller can\nlock it and retry the read."
    }
  ],
  "lastModified": "2026-09-17T17:17:22.640",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}