« Volver al listado

CVE-2026-89518

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Fix this_rq() assumptions in dispatch kfuncs

Under core scheduling, dispatch runs from within the core-wide pick and can target a sibling rq, so ops.dispatch() may execute on a CPU different from the dispatched rq's. Several kfunc paths assumed the two always coincide:

Use the rq tracked by scx_locked_rq(), which is set to the dispatched rq around ops invocations and NULL in unlocked contexts.

Detalles técnicos trazas, registros y código del informe original
- scx_dsq_move() decided whether an rq lock is held by testing this_rq()'s
  rq flags and lock-danced accordingly. A dispatch for a sibling took the
  unlocked-context branch and acquired the source rq lock on top of the
  already held dispatched rq lock which could deadlock.

- scx_bpf_sub_dispatch() dispatched this_rq() with its stashed
  sub_dispatch_prev, which is NULL when dispatching for a sibling.

- finish_dispatch(), scx_bpf_dsq_reenq() and scx_bpf_dsq_nr_queued()
  resolved SCX_DSQ_LOCAL to this CPU's local DSQ rather than the dispatched
  rq's. The latter two are callable from other rq-locked operations too,
  where SCX_DSQ_LOCAL now likewise resolves to the op's rq. This changes
  behavior also without core scheduling, e.g. for ops.enqueue() running a
  remote wakeup on the waking CPU, and is intended: which CPU happens to
  execute an operation is incidental, the op's rq is what it is operating
  on, and the resolution now matches the insert side where SCX_DSQ_LOCAL
  dispatches land on the task's rq.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89518",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4c95380701f58b8112f0b891de8d160e4199e19d",
              "lessThan": "6d1890d3c6137ab523799765ae2de62cc05f116d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4c95380701f58b8112f0b891de8d160e4199e19d",
              "lessThan": "3dd52416e44a70bc993adb96d2e0d71b9ea21359",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/sched/ext/ext.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/sched/ext/ext.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:34.417",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3dd52416e44a70bc993adb96d2e0d71b9ea21359",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6d1890d3c6137ab523799765ae2de62cc05f116d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Fix this_rq() assumptions in dispatch kfuncs\n\nUnder core scheduling, dispatch runs from within the core-wide pick and can\ntarget a sibling rq, so ops.dispatch() may execute on a CPU different from\nthe dispatched rq's. Several kfunc paths assumed the two always coincide:\n\n- scx_dsq_move() decided whether an rq lock is held by testing this_rq()'s\n  rq flags and lock-danced accordingly. A dispatch for a sibling took the\n  unlocked-context branch and acquired the source rq lock on top of the\n  already held dispatched rq lock which could deadlock.\n\n- scx_bpf_sub_dispatch() dispatched this_rq() with its stashed\n  sub_dispatch_prev, which is NULL when dispatching for a sibling.\n\n- finish_dispatch(), scx_bpf_dsq_reenq() and scx_bpf_dsq_nr_queued()\n  resolved SCX_DSQ_LOCAL to this CPU's local DSQ rather than the dispatched\n  rq's. The latter two are callable from other rq-locked operations too,\n  where SCX_DSQ_LOCAL now likewise resolves to the op's rq. This changes\n  behavior also without core scheduling, e.g. for ops.enqueue() running a\n  remote wakeup on the waking CPU, and is intended: which CPU happens to\n  execute an operation is incidental, the op's rq is what it is operating\n  on, and the resolution now matches the insert side where SCX_DSQ_LOCAL\n  dispatches land on the task's rq.\n\nUse the rq tracked by scx_locked_rq(), which is set to the dispatched rq\naround ops invocations and NULL in unlocked contexts."
    }
  ],
  "lastModified": "2026-09-11T20:19:34.417",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}