Race condition in Linux kernel - CVE-2026-89521
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause scheduler selection and accounting inconsistencies.
The vulnerability exists due to a race condition in the core scheduler's pick_next_task() function when handling task selection after pick_task() releases the runqueue lock. A local user can trigger task selection that interleaves with another selection to cause scheduler selection and accounting inconsistencies.