CVE-2026-89566
Received Received - Intake

Denial of Service in Linux Kernel JBD2

Vulnerability report for CVE-2026-89566, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP. The continue statement on this path also skips the need_resched() check at the end of the loop body. Consequently, when a checkpoint list contains mostly busy buffers, the shrinker can walk the entire list while holding journal->j_list_lock, even when a reschedule has been requested. Large checkpoint lists under memory pressure can therefore cause long lock hold times and leave other CPUs spinning on j_list_lock, resulting in soft lockups or RCU stalls. Route the busy-buffer path through the need_resched() check so that the shrinker can release j_list_lock and reschedule promptly, restoring parity with the clean-buffer path, which already checks need_resched(). This does not change which checkpoint buffers are eligible for removal.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the jbd2 component where a shrinker function can hold a lock for too long. When processing checkpoint buffers, the function skips busy buffers but fails to check if the CPU needs to reschedule. This can lead to long lock hold times, causing soft lockups or RCU stalls on other CPUs.

Detection Guidance

This vulnerability is specific to the Linux kernel's jbd2 journaling layer and may manifest as soft lockups or RCU stalls during heavy filesystem activity. Detection typically involves monitoring system logs for lock contention or unresponsiveness. Check for messages like 'soft lockup' or 'RCU stall' in kernel logs using commands like 'dmesg | grep -i lockup' or 'journalctl -k | grep -i stall'.

Impact Analysis

This vulnerability can cause system performance issues, including slowdowns or unresponsiveness due to long lock hold times. In severe cases, it may lead to system freezes or crashes, particularly under memory pressure with large checkpoint lists.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA. It is a Linux kernel issue causing potential soft lockups or RCU stalls due to long lock hold times, which may indirectly impact system availability but does not involve data breaches or unauthorized access.

Mitigation Strategies

Apply the latest Linux kernel updates to patch this issue. If immediate patching is not possible, consider reducing filesystem workload or isolating critical processes to minimize jbd2 journaling activity. Monitor system performance closely for signs of lock contention.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89566. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart