CVE-2026-90262
Description
In the Linux kernel, the following vulnerability has been resolved: btrfs: retry verity reads for not-uptodate Merkle folios btrfs_read_merkle_tree_page() can find a folio in the mapping that is not uptodate. After taking the folio lock, the current code treats that state as a read error and returns -EIO. That can make a previous transient read failure sticky. If the failed read left a not-uptodate folio in the mapping, later callers find that folio and fail instead of retrying the read. Keep the existing page-cache insertion and locking order, but retry the Merkle item read when a not-uptodate folio is found in the mapping. Also unlock the folio when read_key_bytes() fails so that a later caller can lock it and retry the read.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/12b6d1a1715cbced2e445ca353f9c9987b8636e2
- https://git.kernel.org/stable/c/81241f734f0f662378f5ffc53882b012923e6fe5
- https://git.kernel.org/stable/c/8cc569696dac51fc62bb39b3b8f530582b916d29
- https://git.kernel.org/stable/c/90e9eae1b5907fa36620ffb7f4f1a4afa9333427
- https://git.kernel.org/stable/c/c1fa005cdf3b7ff14cdfd7d512830088a3fc256b
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.