« Volver al listado

CVE-2026-89567

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

jbd2: bound shrinker scans by examined checkpoint buffers

The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nr_to_scan. Busy buffers therefore do not consume the scan budget.

If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint list while holding journal->j_list_lock. Large checkpoint lists can result in excessive lock hold times and leave other CPUs spinning on j_list_lock, causing soft lockups or RCU stalls.

Pass nr_to_scan into journal_shrink_one_cp_list() and decrement it for every buffer examined, including busy buffers. Pass NULL from checkpoint cleanup paths so their existing full-list behavior is preserved.

Leer descripción completaMostrar menos

This restores the scan-budget semantics that existed before journal_shrink_one_cp_list() was changed to always scan a complete checkpoint list.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89567",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "b98dba273a0e47dbfade89c9af73c5b012a4eabb",
              "lessThan": "edf5fcd0469b7467bd5b37a79502c8d9c3257dbb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b98dba273a0e47dbfade89c9af73c5b012a4eabb",
              "lessThan": "71c6b872c746465fa4b5def239cb296173ca8216",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b98dba273a0e47dbfade89c9af73c5b012a4eabb",
              "lessThan": "c2c0fb364685b8996c357d3b050394959b29d6e0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b98dba273a0e47dbfade89c9af73c5b012a4eabb",
              "lessThan": "15cb16496446b94e67f7abcb049b8e2c75cd3d02",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "9c31bb2684f8035beca0275349d19d679b679ffb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5fda50e262e65bd553ff777c4b280afd1495a18b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "557fda9ed70ebf8eda2620ba3d746215285a1303",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.15.129",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.50",
              "lessThan": "6.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.4.13",
              "lessThan": "6.5",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "fs/jbd2/checkpoint.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.5"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.5",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.109",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.50",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/jbd2/checkpoint.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:40.680",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/15cb16496446b94e67f7abcb049b8e2c75cd3d02",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/71c6b872c746465fa4b5def239cb296173ca8216",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c2c0fb364685b8996c357d3b050394959b29d6e0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/edf5fcd0469b7467bd5b37a79502c8d9c3257dbb",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: bound shrinker scans by examined checkpoint buffers\n\nThe jbd2 shrinker currently accounts only checkpoint buffers that it\nsuccessfully releases against nr_to_scan.  Busy buffers therefore do not\nconsume the scan budget.\n\nIf a checkpoint transaction contains mostly busy buffers, the shrinker\ncan scan its entire checkpoint list while holding journal->j_list_lock.\nLarge checkpoint lists can result in excessive lock hold times and leave\nother CPUs spinning on j_list_lock, causing soft lockups or RCU stalls.\n\nPass nr_to_scan into journal_shrink_one_cp_list() and decrement it for\nevery buffer examined, including busy buffers.  Pass NULL from checkpoint\ncleanup paths so their existing full-list behavior is preserved.\n\nThis restores the scan-budget semantics that existed before\njournal_shrink_one_cp_list() was changed to always scan a complete\ncheckpoint list."
    }
  ],
  "lastModified": "2026-09-11T20:19:40.680",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}