Integer overflow in Linux kernel - CVE-2026-43323
Published: May 9, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an integer overflow in the CFS scheduler when handling repeated yield operations across runnable tasks. A local user can trigger repeated yield activity to cause a denial of service.
Systems with multiple cgroups may be more exposed because scheduler tick updates may not reach every cgroup in a timely manner.