Answer in brief
CVE-2026-89835 records a Unknown severity vulnerability in f2fs: avoid NULL checkpoint thread access in sysfs. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=e65920661708b7c0f3db45c9cd5d0095034ee37f <a6573f3ffc19542de9ebc1a2b1f930fd48ba538c || >=e65920661708b7c0f3db45c9cd5d0095034ee37f <aefcec3bebdeed2bff444378122300763325ba23 || >=e65920661708b7c0f3db45c9cd5d0095034ee37f <8f3b99c50dd0da1777994ce7c7e60d39b9f60f4b || >=e65920661708b7c0f3db45c9cd5d0095034ee37f <5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f | a6573f3ffc19542de9ebc1a2b1f930fd48ba538c, aefcec3bebdeed2bff444378122300763325ba23, 8f3b99c50dd0da1777994ce7c7e60d39b9f60f4b, 5cb33b00c8fbb6e8f1fa3d281c3036d5f7c7c41f |
| Linux/Linuxgeneric | 5.12 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: f2fs: avoid NULL checkpoint thread access in sysfs checkpoint_merge can be enabled even when no checkpoint merge thread is running. A read-only mount is one case: f2fs does not start f2fs_issue_ckpt there, but ckpt_thread_ioprio is still writable through sysfs. The ckpt_thread_ioprio store path updates the saved ioprio value and, when checkpoint_merge is enabled, calls set_task_ioprio() for the checkpoint thread. If cprc->f2fs_issue_ckpt is NULL, that dereferences a NULL task pointer. Protect ckpt_thread_ioprio sysfs writes with s_umount as well, so the checkpoint thread cannot disappear under the store path while updating its ioprio.
Quoted source text, attributed separately from HOL analysis.