« Volver al listado

CVE-2026-89519

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return

SCX_RQ_BAL_KEEP tells the pick to keep running the previous task, a leftover from when balancing and picking were separate operations. An rq-level flag only works while dispatches and picks pair up one to one, which core scheduling breaks: selections interleave through dispatch's lock drops and a pick can consume a stale flag, keeping a task that has since been dequeued. Fixing core scheduling support requires the decision to travel with the dispatch that made it. Make scx_dispatch_sched() and balance_one() return an explicit verdict instead and drop the flag's plumbing from the tools autogen enum headers.

Leer descripción completaMostrar menos

Also factor the pick-side invocation, its follow-up queueing and the post-dispatch checks out of do_pick_task_scx() into dispatch_pick(). No functional changes intended.

Detalles técnicos trazas, registros y código del informe original
v2: Drop the SCX_RQ_BAL_KEEP plumbing from the tools autogen enum headers
    as well (Andrea).

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89519",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4c95380701f58b8112f0b891de8d160e4199e19d",
              "lessThan": "6f1d3bfe54430f8d54e0530a27f2ecbf8466576e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4c95380701f58b8112f0b891de8d160e4199e19d",
              "lessThan": "ffaab58d217581cb75353168f8812a16e10463fc",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/sched/ext/ext.c",
            "kernel/sched/sched.h",
            "tools/sched_ext/include/scx/enum_defs.autogen.h",
            "tools/sched_ext/include/scx/enums.autogen.bpf.h",
            "tools/sched_ext/include/scx/enums.autogen.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/sched/ext/ext.c",
            "kernel/sched/sched.h",
            "tools/sched_ext/include/scx/enum_defs.autogen.h",
            "tools/sched_ext/include/scx/enums.autogen.bpf.h",
            "tools/sched_ext/include/scx/enums.autogen.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:34.533",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/6f1d3bfe54430f8d54e0530a27f2ecbf8466576e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ffaab58d217581cb75353168f8812a16e10463fc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return\n\nSCX_RQ_BAL_KEEP tells the pick to keep running the previous task, a leftover\nfrom when balancing and picking were separate operations. An rq-level flag\nonly works while dispatches and picks pair up one to one, which core\nscheduling breaks: selections interleave through dispatch's lock drops and a\npick can consume a stale flag, keeping a task that has since been dequeued.\nFixing core scheduling support requires the decision to travel with the\ndispatch that made it. Make scx_dispatch_sched() and balance_one() return an\nexplicit verdict instead and drop the flag's plumbing from the tools autogen\nenum headers.\n\nAlso factor the pick-side invocation, its follow-up queueing and the\npost-dispatch checks out of do_pick_task_scx() into dispatch_pick(). No\nfunctional changes intended.\n\nv2: Drop the SCX_RQ_BAL_KEEP plumbing from the tools autogen enum headers\n    as well (Andrea)."
    }
  ],
  "lastModified": "2026-09-11T20:19:34.533",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}