CVE-2026-89566

In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP. The continue statement on this path also skips the need_resched() check at the end of the loop body. Consequently, when a checkpoint list contains mostly busy buffers, the shrinker can walk the entire list while holding journal->j_list_lock, even when a reschedule has been requested. Large checkpoint lists under memory pressure can therefore cause long lock hold times and leave other CPUs spinning on j_list_lock, resulting in soft lockups or RCU stalls. Route the busy-buffer path through the need_resched() check so that the shrinker can release j_list_lock and reschedule promptly, restoring parity with the clean-buffer path, which already checks need_resched(). This does not change which checkpoint buffers are eligible for removal.

Package Linux Kernel
Published 2026-09-11
Last modified 2026-09-11
Patch available
Yes

Affected versions

Linux kernel versions 5.15.129, 6.1.50, 6.4.13, 6.5 and later are affected. Fixed in 6.12.109, 6.18.50, 7.2.4, 7.3-rc1 and their respective stable series.

Affected from
≥ 5.15.129 ≥ 6.1.50 ≥ 6.4.13 ≥ 6.5
Fixed in
✓ 6.12.109 6.12.x ✓ 6.18.50 6.18.x ✓ 7.2.4 7.2.x ✓ 7.3-rc1

Frequently asked questions

  • What is CVE-2026-89566?

    CVE-2026-89566 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.15.129 onward and has been patched in 6.12.109, 6.18.50, 7.2.4 and others. CVE-2026-89566 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-89566?

    Yes. CVE-2026-89566 has been patched. Fixed versions include 6.12.109, 6.18.50, 7.2.4 and others. If you are running Linux kernel 5.15.129 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-89566 actively exploited?

    No. CVE-2026-89566 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.