{"id":"CVE-2026-89835","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: avoid NULL checkpoint thread access in sysfs\n\ncheckpoint_merge can be enabled even when no checkpoint merge thread is\nrunning","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: avoid NULL checkpoint thread access in sysfs\n\ncheckpoint_merge can be enabled even when no checkpoint merge thread is\nrunning. A read-only mount is one case: f2fs…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= e65920661708b7c0f3db45c9cd5d0095034ee37f < a6573f3ffc19542de9ebc1a2b1f930fd48ba538c","Linux >= e65920661708b7c0f3db45c9cd5d0095034ee37f < aefcec3bebdeed2bff444378122300763325ba23","Linux >= e65920661708b7c0f3db45c9cd5d0095034ee37f < 8f3b99c50dd0da1777994ce7c7e60d39b9f60f4b","Linux >= e65920661708b7c0f3db45c9cd5d0095034ee37f < 5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f","Linux 5.12"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T11:16:50.290","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-89835","references":[{"url":"https://git.kernel.org/stable/c/5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8f3b99c50dd0da1777994ce7c7e60d39b9f60f4b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/a6573f3ffc19542de9ebc1a2b1f930fd48ba538c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/aefcec3bebdeed2bff444378122300763325ba23","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-16T10:53:53.998Z","epss":0.00209,"epssPercentile":0.09773,"slug":"CVE-2026-89835","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: avoid NULL checkpoint thread access in sysfs\n\ncheckpoint_merge can be enabled even when no checkpoint merge thread is\nrunning. A read-only mount is one case: f2fs does not start\nf2fs_issue_ckpt there, but ckpt_thread_ioprio is still writable through\nsysfs.\n\nThe ckpt_thread_ioprio store path updates the saved ioprio value and,\nwhen checkpoint_merge is enabled, calls set_task_ioprio() for the\ncheckpoint thread. If cprc->f2fs_issue_ckpt is NULL, that dereferences a\nNULL task pointer.\n\nProtect ckpt_thread_ioprio sysfs writes with s_umount as well, so the\ncheckpoint thread cannot disappear under the store path while updating\nits ioprio.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}