Executive brief
A vulnerability in the Linux kernel's task scheduler could allow a local user to cause system instability or a denial-of-service. The issue occurs when specific types of background tasks interact in a way that causes internal timing counters to overflow, potentially crashing the system or making it unresponsive. This affects the core component responsible for managing how different programs share the computer's processor.
Technical details
A vulnerability exists in the Linux kernel's 'sched/fair' component due to improper tracking of 'zero_vruntime'. In scenarios where multiple runnable tasks frequently use the yield() system call, they can 'leapfrog' each other's eligibility without triggering a full enqueue/dequeue or a scheduler tick. Because 'zero_vruntime' was previously only updated during ticks or full enqueues, these rapid context switches can cause the virtual runtime to reach an overflow point within a single tick interval. This is particularly problematic in environments with multiple cgroups where ticks may not be processed timely for every group. The fix involves forcing a 'zero_vruntime' update at the end of every execution slice within 'update_deadline()'.
Affected products
- Linux Linux Kernel Versions including EEVDF scheduler changes
Timeline
- 2026-04-01: patched: Initial fix authored by Peter Zijlstra
- 2026-05-08: disclosed: CVE-2026-43323 published