f2fs: avoid NULL checkpoint thread access in sysfs
Summary
| CVE | CVE-2026-89835 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 11:16:50 UTC |
| Updated | 2026-09-16 11:16:50 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
f2fs: avoid NULL checkpoint thread access in sysfs
checkpoint_merge can be enabled even when no checkpoint merge thread is
running. A read-only mount is one case: f2fs does not start
f2fs_issue_ckpt there, but ckpt_thread_ioprio is still writable through
sysfs.
The ckpt_thread_ioprio store path updates the saved ioprio value and,
when checkpoint_merge is enabled, calls set_task_ioprio() for the
checkpoint thread. If cprc->f2fs_issue_ckpt is NULL, that dereferences a
NULL task pointer.
Protect ckpt_thread_ioprio sysfs writes with s_umount as well, so the
checkpoint thread cannot disappear under the store path while updating
its ioprio. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected e65920661708b7c0f3db45c9cd5d0095034ee37f a6573f3ffc19542de9ebc1a2b1f930fd48ba538c git |
Not specified |
| CNA |
Linux |
Linux |
affected e65920661708b7c0f3db45c9cd5d0095034ee37f aefcec3bebdeed2bff444378122300763325ba23 git |
Not specified |
| CNA |
Linux |
Linux |
affected e65920661708b7c0f3db45c9cd5d0095034ee37f 8f3b99c50dd0da1777994ce7c7e60d39b9f60f4b git |
Not specified |
| CNA |
Linux |
Linux |
affected e65920661708b7c0f3db45c9cd5d0095034ee37f 5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f git |
Not specified |
| CNA |
Linux |
Linux |
affected 5.12 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.12 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.110 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.51 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2.5 7.2.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.3-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/8f3b99c50dd0da1777994ce7c7e60d39b9f60f4b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/aefcec3bebdeed2bff444378122300763325ba23 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/a6573f3ffc19542de9ebc1a2b1f930fd48ba538c |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.