Junglewise Threat Intelligence

CVE-2025-39780: Linux Kernel invalid task state transition in sched_ext

CVE-2025-39780 · Severity: high · CVSS 7.8 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's extensible scheduler (sched_ext) could allow a local attacker to cause system instability or potentially escalate privileges. The issue occurs when the system incorrectly handles tasks that are finishing or 'dead' while switching scheduling modes. This can lead to invalid internal states that disrupt normal system operations.

Technical details

A flaw exists in the Linux kernel's sched_ext (SCX) framework during scheduling class transitions. When enabling a sched_ext scheduler, the kernel fails to exclude tasks that are already dead (usage counter at zero) during the transition phase, despite skipping them during initialization. This leads to invalid task state transitions in scx_set_task_state, triggering kernel warnings and potential memory safety issues. A local attacker can exploit this by repeatedly triggering scheduling class switches, such as through hotplug operations, to cause a denial of service or gain elevated privileges. Patches have been released for stable kernel branches including 6.12.44 and 6.16.4.

Affected products

  • Linux Linux Kernel 6.12 to 6.12.43, 6.13 to 6.16.3

Timeline

  • 2025-08-05: other: Fix authored
  • 2025-09-11: disclosed: CVE published
  • 2025-08-28: patched: Fix committed to stable branches

References

Related threats