Improper control of a resource through its lifetime in Linux kernel - CVE-2026-90260
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to corrupt filesystem metadata and cause a denial of service.
The vulnerability exists due to improper control of an extent buffer's lifetime in the Btrfs zoned filesystem write path when writing a freed-but-still-dirty tree block. A local user can trigger writeout of a freed-but-still-dirty tree block to corrupt filesystem metadata and cause a denial of service.