« Volver al listado

CVE-2026-93220

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Keep kick_sync waiting on the rq's own CPU

kick_sync_wait_bal_cb() assumes it runs on the rq's CPU from the __schedule() tail: the snapshots it compares against live in that CPU's percpu area and the busy-wait runs with the rq lock dropped and IRQs enabled.

However, dispatch can now drop the rq lock while the callback sits queued, and rq lock takers in that window (the sched class change paths, the scx task iterator) flush pending balance callbacks on release, running the callback on a foreign CPU. Such a run compares against unrelated snapshots and can deadlock when the executing CPU is itself a wait target.

Leer descripción completaMostrar menos

Bail on a foreign CPU and leave the wait state alone. The wait only observes progress that the resched kicks already guarantee and the rq's next wait picks up the stale cpus_to_sync bits.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93220",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4c95380701f58b8112f0b891de8d160e4199e19d",
              "lessThan": "c736ea0fe7b4df920da6bd43a81c5eeecadcc8be",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4c95380701f58b8112f0b891de8d160e4199e19d",
              "lessThan": "e0253dd04beb03e79477c5ef4768b11135687206",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/sched/ext/ext.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.4",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/sched/ext/ext.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:17.197",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/c736ea0fe7b4df920da6bd43a81c5eeecadcc8be",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e0253dd04beb03e79477c5ef4768b11135687206",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Keep kick_sync waiting on the rq's own CPU\n\nkick_sync_wait_bal_cb() assumes it runs on the rq's CPU from the\n__schedule() tail: the snapshots it compares against live in that CPU's\npercpu area and the busy-wait runs with the rq lock dropped and IRQs\nenabled.\n\nHowever, dispatch can now drop the rq lock while the callback sits queued,\nand rq lock takers in that window (the sched class change paths, the scx\ntask iterator) flush pending balance callbacks on release, running the\ncallback on a foreign CPU. Such a run compares against unrelated snapshots\nand can deadlock when the executing CPU is itself a wait target.\n\nBail on a foreign CPU and leave the wait state alone. The wait only observes\nprogress that the resched kicks already guarantee and the rq's next wait\npicks up the stale cpus_to_sync bits."
    }
  ],
  "lastModified": "2026-09-24T16:17:17.197",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}