CVE-2026-43392 Details
Description
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Fix starvation of scx_enable() under fair-class saturation During scx_enable(), the READY -> ENABLED task switching loop changes the calling thread's sched_class from fair to ext. Since fair has higher priority than ext, saturating fair-class workloads can indefinitely starve the enable thread, hanging the system. This was introduced when the enable path switched from preempt_disable() to scx_bypass() which doesn't protect against fair-class starvation. Note that the original preempt_disable() protection wasn't complete either - in partial switch modes, the calling thread could still be starved after preempt_enable() as it may have been switched to ext class. Fix it by offloading the enable body to a dedicated system-wide RT (SCHED_FIFO) kthread which cannot be starved by either fair or ext class tasks. scx_enable() lazily creates the kthread on first use and passes the ops pointer through a struct scx_enable_cmd containing the kthread_work, then synchronously waits for completion. The workfn runs on a different kthread from sch->helper (which runs disable_work), so it can safely flush disable_work on the error path without deadlock.
A vulnerability in the Linux kernel's scheduling extension can lead to system hangs. During the 'scx_enable()' process, the task switching loop alters the thread's scheduling class from fair to ext. Since the fair class has higher priority, workloads that saturate this class can indefinitely starve the enabling thread, causing the system to freeze. This issue arose when the enabling process shifted from 'preempt_disable()' to 'scx_bypass()', which fails to guard against fair-class starvation. Although the initial 'preempt_disable()' protection was not entirely effective, as it allowed for starvation in partial switch modes, the vulnerability has been addressed by redirecting the enabling process to a dedicated real-time kernel thread that is immune to starvation from both fair and ext class tasks. The 'scx_enable()' function now creates this thread on its first use, ensuring a smoother operation.
Users can update to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/05ab9ec5dc24f234e0a2fecf3e6ff937c68f7d81 | kernel.org | Patch |
| https://git.kernel.org/stable/c/b06ccbabe2506fd70b9167a644978b049150224a | kernel.org | Patch |
| https://git.kernel.org/stable/c/c44198f25fdfecc0ec0fe366bf8a47fe17d8e229 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e0b14bf06393be137d3efb6a3b7cd5b4b9810a6b | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.12.1, < 6.12.78 >= 6.13, < 6.18.20 >= 6.19, < 6.19.9 6.12 - 6.12 rc2 6.12 rc3 6.12 rc4 6.12 rc5 6.12 rc6 6.12 rc7 7.0 rc1 7.0 rc2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| May 26, 2026 | Initial Analysis | [email protected] |
| May 8, 2026 | New CVE Received | kernel.org |