CVE-2026-89567

In the Linux kernel, the following vulnerability has been resolved: jbd2: bound shrinker scans by examined checkpoint buffers The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nr_to_scan. Busy buffers therefore do not consume the scan budget. If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint list while holding journal->j_list_lock. Large checkpoint lists can result in excessive lock hold times and leave other CPUs spinning on j_list_lock, causing soft lockups or RCU stalls. Pass nr_to_scan into journal_shrink_one_cp_list() and decrement it for every buffer examined, including busy buffers. Pass NULL from checkpoint cleanup paths so their existing full-list behavior is preserved. This restores the scan-budget semantics that existed before journal_shrink_one_cp_list() was changed to always scan a complete checkpoint list.

Package Linux Kernel
Published 2026-09-11
Last modified 2026-09-11
Patch available
Yes

Affected versions

Linux kernel versions 5.15.129, 6.1.50, 6.4.13, 6.5 and later are affected. Fixed in 6.12.109, 6.18.50, 7.2.4, 7.3-rc1 and their respective stable series.

Affected from
≥ 5.15.129 ≥ 6.1.50 ≥ 6.4.13 ≥ 6.5
Fixed in
✓ 6.12.109 6.12.x ✓ 6.18.50 6.18.x ✓ 7.2.4 7.2.x ✓ 7.3-rc1

Frequently asked questions

  • What is CVE-2026-89567?

    CVE-2026-89567 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.15.129 onward and has been patched in 6.12.109, 6.18.50, 7.2.4 and others. CVE-2026-89567 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-89567?

    Yes. CVE-2026-89567 has been patched. Fixed versions include 6.12.109, 6.18.50, 7.2.4 and others. If you are running Linux kernel 5.15.129 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-89567 actively exploited?

    No. CVE-2026-89567 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.