Description
In the Linux kernel, the following vulnerability has been resolved:

jbd2: check need_resched() when skipping busy checkpoint buffers

journal_shrink_one_cp_list() skips busy checkpoint buffers when called
with JBD2_SHRINK_BUSY_SKIP. The continue statement on this path also
skips the need_resched() check at the end of the loop body.

Consequently, when a checkpoint list contains mostly busy buffers, the
shrinker can walk the entire list while holding journal->j_list_lock,
even when a reschedule has been requested. Large checkpoint lists under
memory pressure can therefore cause long lock hold times and leave other
CPUs spinning on j_list_lock, resulting in soft lockups or RCU stalls.

Route the busy-buffer path through the need_resched() check so that the
shrinker can release j_list_lock and reschedule promptly, restoring
parity with the clean-buffer path, which already checks need_resched().
This does not change which checkpoint buffers are eligible for removal.
Published: 2026-09-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Soft Lockups
Action: Apply Patch
AI Analysis

Impact

The Linux kernel JBD2 journal shrinker incorrectly bypasses a need_resched() check when it skips busy checkpoint buffers. As a result, buffers the shrinker can walk the entire list while holding the j_list_lock, even if a reschedule has been requested. This prolonged lock hold causes other CPUs to spin on the lock, producing soft lockups and potentially RCU stalls, which degrade system availability but do not crash the kernel.

Affected Systems

All Linux kernel builds prior to the inclusion of commit f83c23286e54180cdc83a36463a60003534cc290 are vulnerable. The fix was merged into the mainline kernel in early 2026, so any kernel version released before that commit lack the remediation. Distribution kernels that have not yet applied the patch or have not incorporated the commit remain at risk.

Risk and Exploitability

The CVSS score of 5.5 indicates a medium severity vulnerability that can lead to service degradation.0.2% suggests that exploitation is unlikely to be widespread at present, and the vulnerability is not listed in CISA’s KEV catalog. The flaw can be triggered by a local user who can generate files under memory pressure, causing the kernel to traverse many busy buffers. Based on the description, the likely attack vector is local access with the ability to produce sustained memory‑pressure workloads; remote exploitation appears infeasible under the current description.

Generated by OpenCVE AI on September 15, 2026 at 21:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains commit f83c23286e54180cdc83a36463a60003534cc290, which reinstates the need_resched() check in the JBD2 shrinker.
  • If a kernel upgrade cannot be performed immediately, consider tuning kernel memory parameters such as vm.min_free_kbytes and vm.overcommit_memory or temporarily limiting the journal size to reduce the number of busy checkpoint buffers under pressure.
  • After applying the patch or updating the kernel, reboot the system to ensure the updated code is active.

Generated by OpenCVE AI on September 15, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-606
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP. The continue statement on this path also skips the need_resched() check at the end of the loop body. Consequently, when a checkpoint list contains mostly busy buffers, the shrinker can walk the entire list while holding journal->j_list_lock, even when a reschedule has been requested. Large checkpoint lists under memory pressure can therefore cause long lock hold times and leave other CPUs spinning on j_list_lock, resulting in soft lockups or RCU stalls. Route the busy-buffer path through the need_resched() check so that the shrinker can release j_list_lock and reschedule promptly, restoring parity with the clean-buffer path, which already checks need_resched(). This does not change which checkpoint buffers are eligible for removal.
Title jbd2: check need_resched() when skipping busy checkpoint buffers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:36.599Z

Reserved: 2026-09-11T19:38:34.726Z

Link: CVE-2026-89566

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:40.550

Modified: 2026-09-11T20:19:40.550

Link: CVE-2026-89566

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:36Z

Links: CVE-2026-89566 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses
  • CWE-606

    Unchecked Input for Loop Condition