CVE-2026-89567
Received Received - Intake

jbd2 Shrinker Lock Contention in Linux Kernel

Vulnerability report for CVE-2026-89567, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: jbd2: bound shrinker scans by examined checkpoint buffers The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nr_to_scan. Busy buffers therefore do not consume the scan budget. If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint list while holding journal->j_list_lock. Large checkpoint lists can result in excessive lock hold times and leave other CPUs spinning on j_list_lock, causing soft lockups or RCU stalls. Pass nr_to_scan into journal_shrink_one_cp_list() and decrement it for every buffer examined, including busy buffers. Pass NULL from checkpoint cleanup paths so their existing full-list behavior is preserved. This restores the scan-budget semantics that existed before journal_shrink_one_cp_list() was changed to always scan a complete checkpoint list.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves the jbd2 shrinker not properly accounting for busy checkpoint buffers during scans. This can lead to excessive lock hold times on j_list_lock, causing soft lockups or RCU stalls if checkpoint transactions contain many busy buffers.

Detection Guidance

This vulnerability is specific to the Linux kernel's jbd2 journaling layer and may not have direct network detection methods. Monitor system logs for soft lockups or RCU stalls, which could indicate excessive j_list_lock hold times. Check kernel messages with 'dmesg | grep -i "soft lockup\|RCU stall"' or 'journalctl -k | grep -i "jbd2\|j_list_lock"'.

Impact Analysis

The vulnerability may cause system performance degradation or instability, such as soft lockups or RCU stalls, due to prolonged lock contention in the journaling subsystem. This could affect overall system responsiveness and reliability.

Mitigation Strategies

Apply the latest Linux kernel patches that address this issue. If immediate patching is not possible, consider reducing filesystem I/O load to minimize checkpoint buffer buildup. Monitor system performance and lock contention closely.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89567. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart