CVE-2026-89566

Summary

In the Linux kernel, the following vulnerability has been resolved:

jbd2: check need_resched() when skipping busy checkpoint buffers

journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP. The continue statement on this path also skips the need_resched() check at the end of the loop body.

Consequently, when a checkpoint list contains mostly busy buffers, the shrinker can walk the entire list while holding journal->j_list_lock, even when a reschedule has been requested. Large checkpoint lists under memory pressure can therefore cause long lock hold times and leave other CPUs spinning on j_list_lock, resulting in soft lockups or RCU stalls.

Route the busy-buffer path through the need_resched() check so that the shrinker can release j_list_lock and reschedule promptly, restoring parity with the clean-buffer path, which already checks need_resched(). This does not change which checkpoint buffers are eligible for removal.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxb98dba273a0e47dbfade89c9af73c5b012a4eabb < f83c23286e54180cdc83a36463a60003534cc290affected
LinuxLinuxb98dba273a0e47dbfade89c9af73c5b012a4eabb < f9182a85991a0ad5cd2940df6db75f40ad90028caffected
LinuxLinuxb98dba273a0e47dbfade89c9af73c5b012a4eabb < 595cac7f1b32d009b97f83dd2b2d6a1a445e9bb4affected
LinuxLinuxb98dba273a0e47dbfade89c9af73c5b012a4eabb < f213e12ff5c9590b1034ae8da0e6d09665c772d0affected
LinuxLinux9c31bb2684f8035beca0275349d19d679b679ffbaffected
LinuxLinux5fda50e262e65bd553ff777c4b280afd1495a18baffected
LinuxLinux557fda9ed70ebf8eda2620ba3d746215285a1303affected
LinuxLinux5.15.129 < 5.16affected
LinuxLinux6.1.50 < 6.2affected
LinuxLinux6.4.13 < 6.5affected
LinuxLinux6.5affected
LinuxLinux0 < 6.5unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References