Impact
The Linux kernel’s jbd2 shrinker currently accounts only for checkpoint buffers it successfully releases when determining how many buffers to scan, effectively busy buffers, the shrinker ends up scanning the entire checkpoint list while holding the journal list lock. This can keep the lock locked for an extended period, causing other CPU cores to spin on the lock and resulting in soft lockups or RCU stalls. The flaw exemplifies uncontrolled resource consumption (CWE‑835) and can reduce system responsiveness without providing direct code execution or data exfiltration.
Affected Systems
Linux kernel builds that contain the unpatched jbd2 shrinker logic are affected. The issue spans all vendor or version numbers until the upstream patch is applied.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, and the EPSS score of less than 1% points to a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The CVE description notes that heavy journaling activity can trigger lock contention leading to soft lockups, but it does not specify an attack vector, privilege level, or the method of triggering the activity. Exploitation requires the ability to generate heavy journaling activity; the CVE description does not specify the exact permissions or local user or higher privilege is needed. Because the flaw does not enable privilege escalation or code execution, it is unlikely to be used in widespread attacks.
OpenCVE Enrichment
Debian DSA