-

CVE-2026-90259

btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()

In the Linux kernel, the following vulnerability has been resolved:

btrfs: qgroup: fix a wrong length calculation in qgroup_free_reserved_data()

In that function, we round down the start position and round up the
ending position.

But during the calculation of @len, we use "round_up(start + len,
sectorsize)", which is the rounded up end position, not the rounded up
length.

Which results a much larger length, and later we are still using
"start + len", which is completely incorrect.

Fix it by declaring a local @aligned_start and @aligned_len and use them
instead.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version bc42bda22345efdb5d8b578d1b4df2c6eaa85c58
Version < e6edde29990af8064b9d12217ec03db231ccd55d
Status affected
Version bc42bda22345efdb5d8b578d1b4df2c6eaa85c58
Version < c4c136555ff90f1e2921cc42da43daac0ef9985e
Status affected
Version bc42bda22345efdb5d8b578d1b4df2c6eaa85c58
Version < 9102b179512e11644fb0489ae62010a09afa199c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.13
Status affected
Version 0
Version < 4.13
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/e6edde29990af8064b9d12217ec03db231ccd55d
https://git.kernel.org/stable/c/c4c136555ff90f1e2921cc42da43daac0ef9985e
https://git.kernel.org/stable/c/9102b179512e11644fb0489ae62010a09afa199c