Answer in brief
CVE-2026-89841 records a Unknown severity vulnerability in f2fs: only redirty pinned folios in redirty_blocks. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5951fee46befbf6176c86482432f4f76e522f16c <445e4a1e6025ecd5312e9a95c1b234192c976ca1 || >=5951fee46befbf6176c86482432f4f76e522f16c <89c65ec3c18903de763cf567c96ab3ef60e5f3b0 || >=5951fee46befbf6176c86482432f4f76e522f16c <85171332742e741ccd6f401c69b6e0d698119e72 | 445e4a1e6025ecd5312e9a95c1b234192c976ca1, 89c65ec3c18903de763cf567c96ab3ef60e5f3b0, 85171332742e741ccd6f401c69b6e0d698119e72 |
| Linux/Linuxgeneric | 6.16 | Not reported |
Published upstream
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 16, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 16, 2026
In the Linux kernel, the following vulnerability has been resolved: f2fs: only redirty pinned folios in redirty_blocks redirty_blocks() pins folios with read_cache_folio() and then walks the same range again with filemap_lock_folio() to redirty them and drop the references it took. Commit 5951fee46bef ("f2fs: Use a folio in redirty_blocks()") changed the second pass to a do/while loop. If read_cache_folio() fails before anything is pinned, page_idx does not advance but the cleanup loop still runs once. If readahead has already populated the failed folio in page cache, that extra iteration finds it and folio_put_refs(folio, 2) drops one reference too many. Later drop_caches or reclaim can then report "BUG: Bad page state". Only redirty the range that was pinned successfully.
Quoted source text, attributed separately from HOL analysis.