CVE-2026-89521Medium· 5.5▾ SunlitA flaw was found in the Linux kernel's core scheduling component. This issue occurs when the `pick_task()` function releases the run queue (rq) lock, allowing an interleaving selection to invalidate the scheduler's internal state. This inc…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.2%
— → 4.7
— → 4.7
none → medium
— → 7.3
none → high
7.3 → 4.7
high → medium
4.7 → 7.3
medium → high
7.3 → 4.7
high → medium
Last analysed / modified upstream
4.7 → 5.5
A flaw was found in the Linux kernel's core scheduling component. This issue occurs when the pick_task() function releases the run queue (rq) lock, allowing an interleaving selection to invalidate the scheduler's internal state. This inconsistency can lead to incorrect task selection and skewed resource accounting, potentially affecting system stability or causing a denial of service.
kernel: sched/core: Handle pick_task() releasing the rq lock — rated Moderate by Red Hat. Released 2026-09-11, updated 2026-09-18.
Affected:
No fix planned:
Not affected:
Fix deferred
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-89503Medium· 5.5kernel: ring-buffer: Fix subbuf resize race with ring_buffer_alloc_read_page() (CVE-2026-89503)
CVE-2026-80927Medium· 5.5kernel: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() (CVE-2026-80927)
CVE-2026-80997Medium· 5.5kernel: net: ipa: fix stalled modem TX queue after runtime resume (CVE-2026-80997)
CVE-2026-89500High· 7.0kernel: ring-buffer: Make cpu_buffer::free_page a buffer_data_read_page (CVE-2026-89500)
CVE-2026-89501High· 7.0kernel: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf (CVE-2026-89501)
CVE-2026-89570High· 7.0kernel: cxl/mce: Make the MCE notifier per-region (CVE-2026-89570)