« Volver al listado

CVE-2026-89521

Estado: RecibidaAlta (7.3)—

In the Linux kernel, the following vulnerability has been resolved:

sched/core: Handle pick_task() releasing the rq lock

Core scheduling's pick_next_task() breaks when a ->pick_task() implementation can release the rq lock. The selection state derived on entry is only valid while the lock is held continuously. Once a pick can drop the lock, an interleaving selection can invalidate all of it: the single-CPU fast path can commit an uncookied pick although the core went cookied during the release, and forceidle committed by the interleaving selection skews the restarted pass's accounting.

Fix it by restarting the whole selection when a pick returns RETRY_TASK after releasing the lock: a single restart point above the state derivation replaces the per-loop restart labels, so a retry picks up state committed by interleaving selections and accounts and resets forceidle like a fresh selection would.

Leer descripción completaMostrar menos

need_sync and fi_before latch across retries. Clock validity can't be re-derived - there is no program-ordered way to tell whether the own and core rq clocks are still updated after the lock was released, as other lockers' pin cycles may or may not have invalidated them. When restarting, clear core_clock_updated so that the sibling loop re-updates the core rq, and update the own rq clock if invalidated.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad local (AV:L/PR:L) en kernel Linux que permite escalada de privilegios mediante race condition en planificación de tareas. Impacto DoS por corrupción de estado de scheduling (forceidle, accounting skew) e integridad de datos por state derivation invalidation.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-89521",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.5,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4c95380701f58b8112f0b891de8d160e4199e19d",
              "lessThan": "88ed5a66467ca2a5148b9997af9c71d8c43060ad",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4c95380701f58b8112f0b891de8d160e4199e19d",
              "lessThan": "c10b216a072ff5c57bc880a05f87eb519aecc529",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/sched/core.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/sched/core.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-11T20:19:34.767",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/88ed5a66467ca2a5148b9997af9c71d8c43060ad",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c10b216a072ff5c57bc880a05f87eb519aecc529",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/core: Handle pick_task() releasing the rq lock\n\nCore scheduling's pick_next_task() breaks when a ->pick_task()\nimplementation can release the rq lock. The selection state derived on entry\nis only valid while the lock is held continuously. Once a pick can drop the\nlock, an interleaving selection can invalidate all of it: the single-CPU\nfast path can commit an uncookied pick although the core went cookied during\nthe release, and forceidle committed by the interleaving selection skews the\nrestarted pass's accounting.\n\nFix it by restarting the whole selection when a pick returns RETRY_TASK\nafter releasing the lock: a single restart point above the state derivation\nreplaces the per-loop restart labels, so a retry picks up state committed by\ninterleaving selections and accounts and resets forceidle like a fresh\nselection would.\n\nneed_sync and fi_before latch across retries. Clock validity can't be\nre-derived - there is no program-ordered way to tell whether the own and\ncore rq clocks are still updated after the lock was released, as other\nlockers' pin cycles may or may not have invalidated them. When restarting,\nclear core_clock_updated so that the sibling loop re-updates the core rq,\nand update the own rq clock if invalidated."
    }
  ],
  "lastModified": "2026-09-13T07:17:14.450",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}