Description
In the Linux kernel, the following vulnerability has been resolved:

f2fs: protect critical_task_priority updates with s_umount

The sysfs store path already takes s_umount for GC thread control
entries, and ckpt_thread_ioprio is covered as well.

critical_task_priority also updates checkpoint or GC kthread scheduling
state, but it is not covered by that serialization. It can race with
remount or teardown paths that are stopping those threads.

Protect critical_task_priority sysfs writes with s_umount too.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via race condition in f2fs scheduler
Action: Apply Patch
AI Analysis

Impact

The vulnerability originates in the f2fs filesystem of the Linux kernel. A write to the critical_task_priority sysfs attribute updates the priority of checkpoint or garbage‑collection threads but the operation is not protected by the s_umount serialization lock, which protects other similar attributes. The race condition allows a concurrent remount or unmount to interfere with the update, potentially setting an invalid or unintended scheduling priority. The result is a denial‑of‑service by suspending or mis‑prioritizing essential background tasks.

Affected Systems

All Linux kernel releases that ship the f2fs filesystem without the patch that adds s_umount guarding for critical_task_priority writes are affected. This includes mainstream distributions' stock kernels as well as custom or older builds that have not applied the fix. The vendor list does not specify a specific distribution, so any distribution deploying f2fs in a kernel version prior to the patch is vulnerable.

Risk and Exploitability

Based on the description, it is inferred that the attack would require an attacker with local access who can write to the f2fs sysfs file. The low EPSS score (<1%) and absence from the CISA KEV catalog indicate that exploitation is unlikely in the wild at this time. Still, the presence of a race condition in a core kernel subsystem justifies prompt patching, as the impact is a denial of service that could affect system stability.

Generated by OpenCVE AI on September 18, 2026 at 09:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the patch protecting critical_task_priority writes.
  • If a kernel upgrade is not immediately possible, restrict write access to the f2fs critical_task_priority sysfs file by adjusting ownership and permissions or applying SELinux/AppArmor rules.
  • Consider unmounting or disabling f2fs temporarily during administrative tasks that could trigger remount or teardown operations to prevent concurrent updates.
  • Monitor system logs for f2fs‑related errors or warnings indicating scheduling anomalies that might result from the race condition.

Generated by OpenCVE AI on September 18, 2026 at 09:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: f2fs: protect critical_task_priority updates with s_umount The sysfs store path already takes s_umount for GC thread control entries, and ckpt_thread_ioprio is covered as well. critical_task_priority also updates checkpoint or GC kthread scheduling state, but it is not covered by that serialization. It can race with remount or teardown paths that are stopping those threads. Protect critical_task_priority sysfs writes with s_umount too.
Title f2fs: protect critical_task_priority updates with s_umount
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:03.702Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89831

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:49.870

Modified: 2026-09-16T11:16:49.870

Link: CVE-2026-89831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses

No weakness.