CVE-2026-90259

Summary

In the Linux kernel, the following vulnerability has been resolved:

btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()

In that function, we round down the start position and round up the ending position.

But during the calculation of @len, we use "round_up(start + len, sectorsize)", which is the rounded up end position, not the rounded up length.

Which results a much larger length, and later we are still using "start + len", which is completely incorrect.

Fix it by declaring a local @aligned_start and @aligned_len and use them instead.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxbc42bda22345efdb5d8b578d1b4df2c6eaa85c58 < e6edde29990af8064b9d12217ec03db231ccd55daffected
LinuxLinuxbc42bda22345efdb5d8b578d1b4df2c6eaa85c58 < c4c136555ff90f1e2921cc42da43daac0ef9985eaffected
LinuxLinuxbc42bda22345efdb5d8b578d1b4df2c6eaa85c58 < 9102b179512e11644fb0489ae62010a09afa199caffected
LinuxLinux4.13affected
LinuxLinux0 < 4.13unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References