---
cve: "CVE-2026-89835"
severity: "LOW"
cvss: 3.1
epss: "0.2%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-09-16 11:16:50"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T18:26:47+02:00"
---

# CVE-2026-89835

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

f2fs: avoid NULL checkpoint thread access in sysfs

checkpoint_merge can be enabled even when no checkpoint merge thread is
running. A read-only mount is one case: f2fs does not start
f2fs_issue_ckpt there, but ckpt_thread_ioprio is still writable through
sysfs.

The ckpt_thread_ioprio store path updates the saved ioprio value and,
when checkpoint_merge is enabled, calls set_task_ioprio() for the
checkpoint thread. If cprc->f2fs_issue_ckpt is NULL, that dereferences a
NULL task pointer.

Protect ckpt_thread_ioprio sysfs writes with s_umount as well, so the
checkpoint thread cannot disappear under the store path while updating
its ioprio.

## Patch verfügbar (OSV)

- Kernel ≥ 6.12.110
- Kernel ≥ 6.18.51
- Kernel ≥ 7.2.5

## Referenzen

- <https://git.kernel.org/stable/c/a6573f3ffc19542de9ebc1a2b1f930fd48ba538c>
- <https://git.kernel.org/stable/c/aefcec3bebdeed2bff444378122300763325ba23>
- <https://git.kernel.org/stable/c/8f3b99c50dd0da1777994ce7c7e60d39b9f60f4b>
- <https://git.kernel.org/stable/c/5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-89835) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
