CVE-2026-89835 PUBLISHED

f2fs: avoid NULL checkpoint thread access in sysfs

Assigner: Linux
Reserved: 11.09.2026 Published: 16.09.2026 Updated: 16.09.2026

In the Linux kernel, the following vulnerability has been resolved:

f2fs: avoid NULL checkpoint thread access in sysfs

checkpoint_merge can be enabled even when no checkpoint merge thread is running. A read-only mount is one case: f2fs does not start f2fs_issue_ckpt there, but ckpt_thread_ioprio is still writable through sysfs.

The ckpt_thread_ioprio store path updates the saved ioprio value and, when checkpoint_merge is enabled, calls set_task_ioprio() for the checkpoint thread. If cprc->f2fs_issue_ckpt is NULL, that dereferences a NULL task pointer.

Protect ckpt_thread_ioprio sysfs writes with s_umount as well, so the checkpoint thread cannot disappear under the store path while updating its ioprio.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from e65920661708b7c0f3db45c9cd5d0095034ee37f to a6573f3ffc19542de9ebc1a2b1f930fd48ba538c (excl.)
  • affected from e65920661708b7c0f3db45c9cd5d0095034ee37f to aefcec3bebdeed2bff444378122300763325ba23 (excl.)
  • affected from e65920661708b7c0f3db45c9cd5d0095034ee37f to 8f3b99c50dd0da1777994ce7c7e60d39b9f60f4b (excl.)
  • affected from e65920661708b7c0f3db45c9cd5d0095034ee37f to 5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 5.12 is affected
  • unaffected from 0 to 5.12 (excl.)
  • unaffected from 6.12.110 to 6.12.* (incl.)
  • unaffected from 6.18.51 to 6.18.* (incl.)
  • unaffected from 7.2.5 to 7.2.* (incl.)
  • unaffected from 7.3-rc1 to * (incl.)

References