{"id":"CVE-2026-89521","title":"kernel: sched/core: Handle pick_task() releasing the rq lock (CVE-2026-89521)","summary":"A flaw was found in the Linux kernel's core scheduling component. This issue occurs when the `pick_task()` function releases the run queue (rq) lock, allowing an interleaving selection to invalidate the scheduler's internal state. This inc…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-367","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10"],"published":"2026-09-11","updated":"2026-09-18","sourceUpdated":"2026-09-18T21:34:35+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89521.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89521.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-89521"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532178"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-89521"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-89521"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-89521.mbox"},{"url":"https://git.kernel.org/stable/c/88ed5a66467ca2a5148b9997af9c71d8c43060ad"},{"url":"https://git.kernel.org/stable/c/c10b216a072ff5c57bc880a05f87eb519aecc529"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00146,"epssPercentile":0.0425,"scores":{"vendor":5.5,"cna":7.3},"ingestedAt":"2026-09-14T15:23:07.475Z","slug":"CVE-2026-89521","body":"## Overview\n\nA flaw was found in the Linux kernel's core scheduling component. This issue occurs when the `pick_task()` function releases the run queue (rq) lock, allowing an interleaving selection to invalidate the scheduler's internal state. This inconsistency can lead to incorrect task selection and skewed resource accounting, potentially affecting system stability or causing a denial of service.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10 · no fix planned: Red Hat Enterprise Linux 10 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-89521.json)\n\n**kernel: sched/core: Handle pick_task() releasing the rq lock** — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":206929,"id":"CVE-2026-89521","ts":1789749703681,"field":"cvss","old":"4.7","new":"5.5"},{"seq":202889,"id":"CVE-2026-89521","ts":1789403732822,"field":"cvss","old":"7.3","new":"4.7"},{"seq":202888,"id":"CVE-2026-89521","ts":1789403732822,"field":"severity","old":"high","new":"medium"},{"seq":197983,"id":"CVE-2026-89521","ts":1789384321248,"field":"cvss","old":"4.7","new":"7.3"},{"seq":197982,"id":"CVE-2026-89521","ts":1789384321248,"field":"severity","old":"medium","new":"high"},{"seq":183496,"id":"CVE-2026-89521","ts":1789356675608,"field":"cvss","old":"7.3","new":"4.7"},{"seq":183495,"id":"CVE-2026-89521","ts":1789356675608,"field":"severity","old":"high","new":"medium"},{"seq":153310,"id":"CVE-2026-89521","ts":1789285349990,"field":"cvss","old":null,"new":"7.3"},{"seq":153309,"id":"CVE-2026-89521","ts":1789285349990,"field":"severity","old":"none","new":"high"},{"seq":147660,"id":"CVE-2026-89521","ts":1789270211780,"field":"cvss","old":null,"new":"4.7"},{"seq":147659,"id":"CVE-2026-89521","ts":1789270211780,"field":"severity","old":"none","new":"medium"},{"seq":109402,"id":"CVE-2026-89521","ts":1789183731775,"field":"cvss","old":null,"new":"4.7"},{"seq":109401,"id":"CVE-2026-89521","ts":1789183731775,"field":"severity","old":"none","new":"medium"}]}