CVE-2026-89567

Summary

In the Linux kernel, the following vulnerability has been resolved:

jbd2: bound shrinker scans by examined checkpoint buffers

The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nr_to_scan. Busy buffers therefore do not consume the scan budget.

If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint list while holding journal->j_list_lock. Large checkpoint lists can result in excessive lock hold times and leave other CPUs spinning on j_list_lock, causing soft lockups or RCU stalls.

Pass nr_to_scan into journal_shrink_one_cp_list() and decrement it for every buffer examined, including busy buffers. Pass NULL from checkpoint cleanup paths so their existing full-list behavior is preserved.

This restores the scan-budget semantics that existed before journal_shrink_one_cp_list() was changed to always scan a complete checkpoint list.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxb98dba273a0e47dbfade89c9af73c5b012a4eabb < edf5fcd0469b7467bd5b37a79502c8d9c3257dbbaffected
LinuxLinuxb98dba273a0e47dbfade89c9af73c5b012a4eabb < 71c6b872c746465fa4b5def239cb296173ca8216affected
LinuxLinuxb98dba273a0e47dbfade89c9af73c5b012a4eabb < c2c0fb364685b8996c357d3b050394959b29d6e0affected
LinuxLinuxb98dba273a0e47dbfade89c9af73c5b012a4eabb < 15cb16496446b94e67f7abcb049b8e2c75cd3d02affected
LinuxLinux9c31bb2684f8035beca0275349d19d679b679ffbaffected
LinuxLinux5fda50e262e65bd553ff777c4b280afd1495a18baffected
LinuxLinux557fda9ed70ebf8eda2620ba3d746215285a1303affected
LinuxLinux5.15.129 < 5.16affected
LinuxLinux6.1.50 < 6.2affected
LinuxLinux6.4.13 < 6.5affected
LinuxLinux6.5affected
LinuxLinux0 < 6.5unaffected
LinuxLinux6.12.109 <= 6.12.*unaffected
LinuxLinux6.18.50 <= 6.18.*unaffected
LinuxLinux7.2.4 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References