Race condition in Linux kernel - CVE-2026-89517
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in the sched_ext core scheduling task-selection logic when task selections interleave after dispatch releases the runqueue lock. A local user can trigger a cookied ping-pong workload to cause a denial of service.
Exploitation requires core scheduling on an SMT system.