CVE-2026-89567: jbd2: bound shrinker scans by examined checkpoint buffers
In the Linux kernel, the following vulnerability has been resolved:
jbd2: bound shrinker scans by examined checkpoint buffers
The jbd2 shrinker currently accounts only checkpoint buffers that it successfully releases against nrtoscan. Busy buffers therefore do not consume the scan budget.
If a checkpoint transaction contains mostly busy buffers, the shrinker can scan its entire checkpoint list while holding journal->jlistlock. Large checkpoint lists can result in excessive lock hold times and leave other CPUs spinning on jlistlock, causing soft lockups or RCU stalls.
Pass nrtoscan into journalshrinkonecplist() and decrement it for every buffer examined, including busy buffers. Pass NULL from checkpoint cleanup paths so their existing full-list behavior is preserved.
This restores the scan-budget semantics that existed before journalshrinkonecplist() was changed to always scan a complete checkpoint list.