{"id":"CVE-2026-89566","title":"In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: check need_resched() when skipping busy checkpoint buffers\n\njournal_shrink_one_cp_list() skips busy checkpoint buffers when called\nwith JBD2_SHRINK_BUSY_SKIP","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: check need_resched() when skipping busy checkpoint buffers\n\njournal_shrink_one_cp_list() skips busy checkpoint buffers when called\nwith JBD2_SHRINK_BUSY_SKIP.  Th…","severity":"medium","vendor":"Linux","product":"Linux","affected":["Linux >= b98dba273a0e47dbfade89c9af73c5b012a4eabb < f83c23286e54180cdc83a36463a60003534cc290","Linux >= b98dba273a0e47dbfade89c9af73c5b012a4eabb < f9182a85991a0ad5cd2940df6db75f40ad90028c","Linux >= b98dba273a0e47dbfade89c9af73c5b012a4eabb < 595cac7f1b32d009b97f83dd2b2d6a1a445e9bb4","Linux >= b98dba273a0e47dbfade89c9af73c5b012a4eabb < f213e12ff5c9590b1034ae8da0e6d09665c772d0","Linux 9c31bb2684f8035beca0275349d19d679b679ffb","Linux 5fda50e262e65bd553ff777c4b280afd1495a18b","Linux 557fda9ed70ebf8eda2620ba3d746215285a1303","Linux >= 5.15.129 < 5.16","Linux >= 6.1.50 < 6.2","Linux >= 6.4.13 < 6.5","Linux 6.5"],"published":"2026-09-11","updated":"2026-09-11","sourceUpdated":"2026-09-11T20:19:40.550","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89566","references":[{"url":"https://git.kernel.org/stable/c/595cac7f1b32d009b97f83dd2b2d6a1a445e9bb4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f213e12ff5c9590b1034ae8da0e6d09665c772d0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f83c23286e54180cdc83a36463a60003534cc290","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f9182a85991a0ad5cd2940df6db75f40ad90028c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89566.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89566"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532052"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89566"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89566"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89566.mbox"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ingestedAt":"2026-09-14T13:21:23.054Z","epss":0.002,"epssPercentile":0.10132,"cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-606"],"slug":"CVE-2026-89566","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\njbd2: check need_resched() when skipping busy checkpoint buffers\n\njournal_shrink_one_cp_list() skips busy checkpoint buffers when called\nwith JBD2_SHRINK_BUSY_SKIP.  The continue statement on this path also\nskips the need_resched() check at the end of the loop body.\n\nConsequently, when a checkpoint list contains mostly busy buffers, the\nshrinker can walk the entire list while holding journal->j_list_lock,\neven when a reschedule has been requested.  Large checkpoint lists under\nmemory pressure can therefore cause long lock hold times and leave other\nCPUs spinning on j_list_lock, resulting in soft lockups or RCU stalls.\n\nRoute the busy-buffer path through the need_resched() check so that the\nshrinker can release j_list_lock and reschedule promptly, restoring\nparity with the clean-buffer path, which already checks need_resched().\nThis does not change which checkpoint buffers are eligible for removal.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89566.json)","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":204201,"id":"CVE-2026-89566","ts":1789490240145,"field":"cvss","old":null,"new":"5.5"},{"seq":204200,"id":"CVE-2026-89566","ts":1789490240145,"field":"severity","old":"none","new":"medium"},{"seq":147800,"id":"CVE-2026-89566","ts":1789270212338,"field":"cvss","old":null,"new":"5.5"},{"seq":147799,"id":"CVE-2026-89566","ts":1789270212338,"field":"severity","old":"none","new":"medium"},{"seq":109556,"id":"CVE-2026-89566","ts":1789183732401,"field":"cvss","old":null,"new":"5.5"},{"seq":109555,"id":"CVE-2026-89566","ts":1789183732401,"field":"severity","old":"none","new":"medium"}]}