Description
In the Linux kernel, the following vulnerability has been resolved:

f2fs: avoid NULL checkpoint thread access in sysfs

checkpoint_merge can be enabled even when no checkpoint merge thread is
running. A read-only mount is one case: f2fs does not start
f2fs_issue_ckpt there, but ckpt_thread_ioprio is still writable through
sysfs.

The ckpt_thread_ioprio store path updates the saved ioprio value and,
when checkpoint_merge is enabled, calls set_task_ioprio() for the
checkpoint thread. If cprc->f2fs_issue_ckpt is NULL, that dereferences a
NULL task pointer.

Protect ckpt_thread_ioprio sysfs writes with s_umount as well, so the
checkpoint thread cannot disappear under the store path while updating
its ioprio.
Published: 2026-09-16
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel null pointer dereference potentially causing a system crash
Action: Patch Immediately
AI Analysis

Impact

This vulnerability in the Linux kernel allows a NULL pointer dereference when the ckpt_thread_ioprio sysfs attribute is written while checkpoint_merge is enabled and the checkpoint thread is not running. The dereference occurs on cprc->f2fs_issue_ckpt when it is NULL, leading to a kernel panic. The impact is a denial of service for the local system, as the crash terminates all running processes and requires a reboot. The weakness is a classic NULL pointer dereference identified by CWE‑476.

Affected Systems

The defect exists in the Linux kernel for all distributions that include the f2fs filesystem driver. The affected code path is part of the ckpt_thread management in f2fs. No specific kernel release is listed, so any kernel version containing the unpatched ckpt_thread_ioprio sysfs write is vulnerable, which includes mainstream releases in 2026.

Risk and Exploitability

The Enterprise Package Security Score (EPSS) for this issue is listed as under 1%, indicating a very low probability of exploitation. It is not listed in the CISA Known Exploited Vulnerabilities catalog (KEV), so no public exploit has been documented. The vulnerability requires local write access to the sysfs attribute controlling checkpoint merge, which typically requires root privileges or an unprivileged user with permission to write directly to sysfs. The attack vector is therefore likely local, but a malicious process with sufficient privileges can crash the host. The severity is ambiguous due to missing CVSS data, but the potential for an imminent kernel crash warrants immediate patching.

Generated by OpenCVE AI on September 18, 2026 at 09:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the f2fs ckpt_thread_ioprio patch or downstream kernel release that fixes the NULL dereference
  • If upgrading is not immediately possible, disable checkpoint_merge by setting the sysfs attribute to 0 or make the sysfs path read‑only so that no writes can occur when a checkpoint thread is absent
  • Monitor system logs and crash dumps for signs of kernel panic and configure automated recovery or alerting to react quickly to a crash

Generated by OpenCVE AI on September 18, 2026 at 09:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: f2fs: avoid NULL checkpoint thread access in sysfs checkpoint_merge can be enabled even when no checkpoint merge thread is running. A read-only mount is one case: f2fs does not start f2fs_issue_ckpt there, but ckpt_thread_ioprio is still writable through sysfs. The ckpt_thread_ioprio store path updates the saved ioprio value and, when checkpoint_merge is enabled, calls set_task_ioprio() for the checkpoint thread. If cprc->f2fs_issue_ckpt is NULL, that dereferences a NULL task pointer. Protect ckpt_thread_ioprio sysfs writes with s_umount as well, so the checkpoint thread cannot disappear under the store path while updating its ioprio.
Title f2fs: avoid NULL checkpoint thread access in sysfs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T10:31:08.636Z

Reserved: 2026-09-11T19:38:34.769Z

Link: CVE-2026-89835

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:16:50.290

Modified: 2026-09-16T11:16:50.290

Link: CVE-2026-89835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses