CVE-2026-89835
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
f2fs: avoid NULL checkpoint thread access in sysfs
checkpoint_merge can be enabled even when no checkpoint merge thread is running. A read-only mount is one case: f2fs does not start f2fs_issue_ckpt there, but ckpt_thread_ioprio is still writable through sysfs.
The ckpt_thread_ioprio store path updates the saved ioprio value and, when checkpoint_merge is enabled, calls set_task_ioprio() for the checkpoint thread. If cprc->f2fs_issue_ckpt is NULL, that dereferences a NULL task pointer.
Protect ckpt_thread_ioprio sysfs writes with s_umount as well, so the checkpoint thread cannot disappear under the store path while updating its ioprio.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | e65920661708b7c0f3db45c9cd5d0095034ee37f < a6573f3ffc19542de9ebc1a2b1f930fd48ba538c | affected |
| Linux | Linux | e65920661708b7c0f3db45c9cd5d0095034ee37f < aefcec3bebdeed2bff444378122300763325ba23 | affected |
| Linux | Linux | e65920661708b7c0f3db45c9cd5d0095034ee37f < 8f3b99c50dd0da1777994ce7c7e60d39b9f60f4b | affected |
| Linux | Linux | e65920661708b7c0f3db45c9cd5d0095034ee37f < 5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f | affected |
| Linux | Linux | 5.12 | affected |
| Linux | Linux | 0 < 5.12 | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/a6573f3ffc19542de9ebc1a2b1f930fd48ba538c
- https://git.kernel.org/stable/c/aefcec3bebdeed2bff444378122300763325ba23
- https://git.kernel.org/stable/c/8f3b99c50dd0da1777994ce7c7e60d39b9f60f4b
- https://git.kernel.org/stable/c/5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.