CVE-2026-89516
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users
scx_bpf_dsq_reenq() queues a deferred reenq (dru) that runs from run_deferred(), not ops.dispatch(). If the DSQ is destroyed before the dru runs, process_deferred_reenq_users() sees dsq->id == SCX_DSQ_INVALID and hits the BUG_ON. destroy_dsq() doesn't flush pending drus, so just skip.
tj: Read dsq->id once with READ_ONCE(). Reading it separately in the INVALID check and the BUG_ON would leave a window where destroy_dsq() can invalidate the id between the two reads and still trigger the BUG_ON.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 84b1a0ea0b7c23dec240783a592e480780efe459 < c480961a1e790b46ffd8c20c4b6754d65ec6572d | affected |
| Linux | Linux | 84b1a0ea0b7c23dec240783a592e480780efe459 < 8d8dd8ae89eaa78b37fc85528e926029f5facbdf | affected |
| Linux | Linux | 7.1 | affected |
| Linux | Linux | 0 < 7.1 | unaffected |
| Linux | Linux | 7.2.4 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/c480961a1e790b46ffd8c20c4b6754d65ec6572d
- https://git.kernel.org/stable/c/8d8dd8ae89eaa78b37fc85528e926029f5facbdf
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.