Executive brief
The Linux kernel's btrfs filesystem has a flaw in how it handles metadata reservation errors on zoned storage devices. When the filesystem temporarily cannot reserve space during block-group reclaim operations, the system unnecessarily forces the filesystem into read-only mode, disrupting normal operations. This patch corrects the logic to treat transient errors as retriable rather than fatal conditions.
Technical details
The vulnerability is a logic error in the btrfs zoned block-group reclaim path. When btrfs_delayed_refs_rsv_refill() returns -EAGAIN (a transient, retriable condition indicating temporary metadata over-commitment), the code was treating it as a fatal error and forcing the filesystem read-only. The root cause is improper error handling in the relocation merge logic (fs/btrfs/relocation.c and fs/btrfs/block-group.c). The fix distinguishes between transient -EAGAIN errors and actual failures: for zoned filesystems, -EAGAIN is now handled as a soft, deferred retry condition rather than aborting the transaction. No authentication or network access is required; the vulnerability manifests only on zoned storage (SMR/CMR) under specific reclaim conditions.
Affected products
- Linux Linux kernel affected versions not explicitly specified in advisory
Timeline
- 2026-09-17: disclosed: CVE-2026-90266 published
- 2026-08-07: patched: Upstream fix merged (commit e549093c11a2fff8430df3dfbdb45eb9811a69a5)
- 2026-06-23: other: Fix authored by Johannes Thumshirn