CVE-2026-89567

Unknown

Last modified

CVE-2026-89567 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: jbd2: bound shrinker scans by examined checkpoint buffers The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nr_to_scan. Busy buffers therefore do not consume the scan budget. If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint list while holding journal->j_list_lock. Large checkpoint lists can result in excessive lock hold times and leave other CPUs spinning on j_list_lock, causing soft lockups or RCU stalls. Pass nr_to_scan into journal_shrink_one_cp_list() and decrement it for every buffer examined, including busy buffers.

Description

In the Linux kernel, the following vulnerability has been resolved: jbd2: bound shrinker scans by examined checkpoint buffers The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nr_to_scan. Busy buffers therefore do not consume the scan budget. If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint list while holding journal->j_list_lock. Large checkpoint lists can result in excessive lock hold times and leave other CPUs spinning on j_list_lock, causing soft lockups or RCU stalls. Pass nr_to_scan into journal_shrink_one_cp_list() and decrement it for every buffer examined, including busy buffers. Pass NULL from checkpoint cleanup paths so their existing full-list behavior is preserved. This restores the scan-budget semantics that existed before journal_shrink_one_cp_list() was changed to always scan a complete checkpoint list.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= b98dba273a0e47dbfade89c9af73c5b012a4eabb, < edf5fcd0469b7467bd5b37a79502c8d9c3257dbb; >= b98dba273a0e47dbfade89c9af73c5b012a4eabb, < 71c6b872c746465fa4b5def239cb296173ca8216; >= b98dba273a0e47dbfade89c9af73c5b012a4eabb, < c2c0fb364685b8996c357d3b050394959b29d6e0; >= b98dba273a0e47dbfade89c9af73c5b012a4eabb, < 15cb16496446b94e67f7abcb049b8e2c75cd3d02; 9c31bb2684f8035beca0275349d19d679b679ffb; 5fda50e262e65bd553ff777c4b280afd1495a18b; 557fda9ed70ebf8eda2620ba3d746215285a1303; >= 5.15.129, < 5.16; >= 6.1.50, < 6.2; >= 6.4.13, < 6.5
LinuxLinux6.5

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-89567?
In the Linux kernel, the following vulnerability has been resolved: jbd2: bound shrinker scans by examined checkpoint buffers The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nr_to_scan. Busy buffers therefore do not consume the scan budget. If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint list while holding journal->j_list_lock. Large checkpoint lists can result in excessive lock hold times and leave other CPUs spinning on j_list_lock, causing soft lockups or RCU stalls. Pass nr_to_scan into journal_shrink_one_cp_list() and decrement it for every buffer examined, including busy buffers. Pass NULL from checkpoint cleanup paths so their existing full-list behavior is preserved. This restores the scan-budget semantics that existed before journal_shrink_one_cp_list() was changed to always scan a complete checkpoint list.
How severe is CVE-2026-89567?
Severity scoring for CVE-2026-89567 is pending analysis.
How do I fix CVE-2026-89567?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-89567?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST