CVE-2026-90262

Source
https://cve.org/CVERecord?id=CVE-2026-90262
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90262.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-90262
Downstream
Published
2026-09-17T16:07:59Z
Modified
2026-09-18T03:48:36Z
Summary
btrfs: retry verity reads for not-uptodate Merkle folios
Details

In the Linux kernel, the following vulnerability has been resolved:

btrfs: retry verity reads for not-uptodate Merkle folios

btrfs_read_merkle_tree_page() can find a folio in the mapping that is not uptodate. After taking the folio lock, the current code treats that state as a read error and returns -EIO.

That can make a previous transient read failure sticky. If the failed read left a not-uptodate folio in the mapping, later callers find that folio and fail instead of retrying the read.

Keep the existing page-cache insertion and locking order, but retry the Merkle item read when a not-uptodate folio is found in the mapping. Also unlock the folio when read_key_bytes() fails so that a later caller can lock it and retry the read.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90262.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
06ed09351b67eb1114ae106a87a0ee3ea9adb3db
Fixed
90e9eae1b5907fa36620ffb7f4f1a4afa9333427
Fixed
c1fa005cdf3b7ff14cdfd7d512830088a3fc256b
Fixed
12b6d1a1715cbced2e445ca353f9c9987b8636e2
Fixed
81241f734f0f662378f5ffc53882b012923e6fe5
Fixed
8cc569696dac51fc62bb39b3b8f530582b916d29

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90262.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.6.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90262.json"