Description
In the Linux kernel, the following vulnerability has been resolved:

jbd2: bound shrinker scans by examined checkpoint buffers

The jbd2 shrinker currently accounts only checkpoint buffers that it
successfully releases against nr_to_scan. Busy buffers therefore do not
consume the scan budget.

If a checkpoint transaction contains mostly busy buffers, the shrinker
can scan its entire checkpoint list while holding journal->j_list_lock.
Large checkpoint lists can result in excessive lock hold times and leave
other CPUs spinning on j_list_lock, causing soft lockups or RCU stalls.

Pass nr_to_scan into journal_shrink_one_cp_list() and decrement it for
every buffer examined, including busy buffers. Pass NULL from checkpoint
cleanup paths so their existing full-list behavior is preserved.

This restores the scan-budget semantics that existed before
journal_shrink_one_cp_list() was changed to always scan a complete
checkpoint list.
Published: 2026-09-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via soft lockups
Action: Patch Kernel
AI Analysis

Impact

The Linux kernel’s jbd2 shrinker currently accounts only for checkpoint buffers it successfully releases when determining how many buffers to scan, effectively busy buffers, the shrinker ends up scanning the entire checkpoint list while holding the journal list lock. This can keep the lock locked for an extended period, causing other CPU cores to spin on the lock and resulting in soft lockups or RCU stalls. The flaw exemplifies uncontrolled resource consumption (CWE‑835) and can reduce system responsiveness without providing direct code execution or data exfiltration.

Affected Systems

Linux kernel builds that contain the unpatched jbd2 shrinker logic are affected. The issue spans all vendor or version numbers until the upstream patch is applied.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, and the EPSS score of less than 1% points to a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The CVE description notes that heavy journaling activity can trigger lock contention leading to soft lockups, but it does not specify an attack vector, privilege level, or the method of triggering the activity. Exploitation requires the ability to generate heavy journaling activity; the CVE description does not specify the exact permissions or local user or higher privilege is needed. Because the flaw does not enable privilege escalation or code execution, it is unlikely to be used in widespread attacks.

Generated by OpenCVE AI on September 15, 2026 at 22:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel release that contains the updated jbd2 shrinker logic so that the new shrinker code takes effect.
  • If an immediate kernel upgrade is not possible, reduce journaling pressure by adjusting checkpoint lists and reducing the number of busy buffers until the patch can be applied.
  • Monitor kernel logs for repeated journal lock contention or soft lockups and alert administrators if thresholds are exceeded.

Generated by OpenCVE AI on September 15, 2026 at 22:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-835
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: jbd2: bound shrinker scans by examined checkpoint buffers The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nr_to_scan. Busy buffers therefore do not consume the scan budget. If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint list while holding journal->j_list_lock. Large checkpoint lists can result in excessive lock hold times and leave other CPUs spinning on j_list_lock, causing soft lockups or RCU stalls. Pass nr_to_scan into journal_shrink_one_cp_list() and decrement it for every buffer examined, including busy buffers. Pass NULL from checkpoint cleanup paths so their existing full-list behavior is preserved. This restores the scan-budget semantics that existed before journal_shrink_one_cp_list() was changed to always scan a complete checkpoint list.
Title jbd2: bound shrinker scans by examined checkpoint buffers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:37.332Z

Reserved: 2026-09-11T19:38:34.726Z

Link: CVE-2026-89567

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:40.680

Modified: 2026-09-11T20:19:40.680

Link: CVE-2026-89567

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:37Z

Links: CVE-2026-89567 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:30:15Z

Weaknesses
  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')