Junglewise Threat Intelligence

CVE-2026-23371: Linux Kernel deadline scheduler bandwidth corruption in PI de-boosting

CVE-2026-23371 · Severity: medium · CVSS 5.5 · Published 2026-03-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's task scheduling system could allow a local user to cause a system crash or instability. The issue occurs when the system incorrectly handles priority changes for tasks that are holding certain locks, leading to internal accounting errors. This can result in kernel warnings or a complete system denial of service, impacting the availability of critical operations.

Technical details

A vulnerability in 'kernel/sched/deadline.c' and 'kernel/sched/syscalls.c' occurs when a SCHED_DEADLINE task holding a PI mutex is moved to a lower priority class via 'sched_setscheduler()'. If the task had not previously inherited parameters from a donor (due to having a shorter deadline at the time), it may fail to inherit them during the policy change. This results in the 'ENQUEUE_REPLENISH' flag being missed, causing 'running_bw' underflows and bandwidth accounting corruption. An attacker with local access can trigger this condition to cause kernel warnings or a system crash (DoS). The fix introduces '__setscheduler_dl_pi()' to ensure proper parameter inheritance and replenishment during such transitions.

Affected products

  • Linux Linux Kernel 4.19.257 to 4.20, 5.4.212 to 5.5, 5.10.1 to 6.19.7, 7.0-rc1 to 7.0-rc7

Timeline

  • 2026-03-02: patched: Initial patch authored by Juri Lelli
  • 2026-03-25: disclosed: CVE-2026-23371 published
  • 2026-03-25: advisory: NVD record created

References

Related threats