Impact
The Linux kernel JBD2 journal shrinker incorrectly bypasses a need_resched() check when it skips busy checkpoint buffers. As a result, buffers the shrinker can walk the entire list while holding the j_list_lock, even if a reschedule has been requested. This prolonged lock hold causes other CPUs to spin on the lock, producing soft lockups and potentially RCU stalls, which degrade system availability but do not crash the kernel.
Affected Systems
All Linux kernel builds prior to the inclusion of commit f83c23286e54180cdc83a36463a60003534cc290 are vulnerable. The fix was merged into the mainline kernel in early 2026, so any kernel version released before that commit lack the remediation. Distribution kernels that have not yet applied the patch or have not incorporated the commit remain at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity vulnerability that can lead to service degradation.0.2% suggests that exploitation is unlikely to be widespread at present, and the vulnerability is not listed in CISA’s KEV catalog. The flaw can be triggered by a local user who can generate files under memory pressure, causing the kernel to traverse many busy buffers. Based on the description, the likely attack vector is local access with the ability to produce sustained memory‑pressure workloads; remote exploitation appears infeasible under the current description.
OpenCVE Enrichment
Debian DSA