CVE-2026-89518
Received Received - Intake

Race Condition in Linux Kernel Sched Ext

Vulnerability report for CVE-2026-89518, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix this_rq() assumptions in dispatch kfuncs Under core scheduling, dispatch runs from within the core-wide pick and can target a sibling rq, so ops.dispatch() may execute on a CPU different from the dispatched rq's. Several kfunc paths assumed the two always coincide: - scx_dsq_move() decided whether an rq lock is held by testing this_rq()'s rq flags and lock-danced accordingly. A dispatch for a sibling took the unlocked-context branch and acquired the source rq lock on top of the already held dispatched rq lock which could deadlock. - scx_bpf_sub_dispatch() dispatched this_rq() with its stashed sub_dispatch_prev, which is NULL when dispatching for a sibling. - finish_dispatch(), scx_bpf_dsq_reenq() and scx_bpf_dsq_nr_queued() resolved SCX_DSQ_LOCAL to this CPU's local DSQ rather than the dispatched rq's. The latter two are callable from other rq-locked operations too, where SCX_DSQ_LOCAL now likewise resolves to the op's rq. This changes behavior also without core scheduling, e.g. for ops.enqueue() running a remote wakeup on the waking CPU, and is intended: which CPU happens to execute an operation is incidental, the op's rq is what it is operating on, and the resolution now matches the insert side where SCX_DSQ_LOCAL dispatches land on the task's rq. Use the rq tracked by scx_locked_rq(), which is set to the dispatched rq around ops invocations and NULL in unlocked contexts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-10-01
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves incorrect assumptions in the sched_ext component's dispatch functions. Under core scheduling, dispatch operations may run on a different CPU than the target run queue (rq), but several kernel functions assumed they always run on the same CPU. This led to potential deadlocks when functions like scx_dsq_move() incorrectly handled rq locks, or when functions like scx_bpf_sub_dispatch() used the wrong CPU's data structures.

Detection Guidance

This vulnerability is specific to the Linux kernel's sched_ext subsystem and requires kernel-level inspection. Detection involves checking kernel logs for related errors or verifying the kernel version against patched releases. Commands like 'uname -r' to check kernel version and 'dmesg | grep sched_ext' to inspect logs may help identify issues.

Impact Analysis

This vulnerability could cause system instability, including deadlocks or crashes, particularly in systems using the Linux kernel with core scheduling enabled. It may lead to unexpected behavior in workload scheduling, performance degradation, or complete system unresponsiveness if exploited or triggered under specific conditions.

Compliance Impact

This vulnerability is specific to the Linux kernel's sched_ext component and does not directly impact compliance with standards like GDPR or HIPAA. It involves a scheduling deadlock issue in core scheduling operations, which is unrelated to data protection or privacy requirements.

Mitigation Strategies

Apply the latest kernel patches that address this issue. If using a distribution kernel, update via package manager (e.g., 'apt upgrade' or 'yum update'). For custom kernels, recompile with the fix. Disable sched_ext features if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-89518. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart