Junglewise Threat Intelligence

CVE-2026-43326: Linux Kernel deadlock in sched_ext SCX_KICK_WAIT

CVE-2026-43326 · Severity: medium · CVSS 5.5 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's scheduling extensible (sched_ext) framework could allow a local user to cause a system deadlock. This component is responsible for managing how the operating system allocates processor time to different tasks. An exploit could lead to a complete system hang, resulting in a denial of service and requiring a hard reboot.

Technical details

A deadlock vulnerability was identified in the Linux kernel's sched_ext (SCX) scheduler class. The issue resides in the SCX_KICK_WAIT mechanism within kick_cpus_irq_workfn(), which performs a busy-wait using smp_cond_load_acquire() until a target CPU's kick_sync counter advances. Because this occurs in a hardirq context, the waiting CPU is unable to reschedule or advance its own kick_sync, potentially creating a cyclic dependency and a system-wide deadlock if multiple CPUs wait on each other. The fix involves deferring the wait to a balance callback that can safely drop the runqueue (rq) lock and enable interrupts, allowing the CPU to process IPIs and avoid the deadlock. The vulnerability affects Linux kernel versions 6.12 and newer.

Affected products

  • Linux Linux Kernel v6.12+

Timeline

  • 2026-03-28: patched: Initial fix authored by Tejun Heo
  • 2026-05-08: advisory: CVE-2026-43326 published

References

Related threats