Executive brief
The Linux kernel's scheduler extension (sched_ext) module contains a lock state tracking bug that can cause assertion failures when moving tasks between dispatch queues. While not directly exploitable for privilege escalation or data theft, this bug can trigger kernel crashes and system instability during scheduler operations, disrupting service availability.
Technical details
This vulnerability is a lock state desynchronization bug in the sched_ext scheduler subsystem. The root cause is that dispatch_to_local_dsq() can trigger nested rq (runqueue) lock handoffs through the ops.dispatch() callback chain, but the rq tracking state is not consistently updated when lock ownership transfers between runqueues. This causes update_locked_rq() to attempt operations on an rq that is no longer held, triggering a lockdep assertion failure. The fix introduces switch_rq_lock() to atomically update the rq tracking state together with each lock handoff in dispatch_to_local_dsq(), move_remote_task_to_local_dsq(), and scx_dsq_move(). The vulnerability requires the sched_ext subsystem to be active with a dispatch operation in progress, making it primarily a kernel stability issue rather than a security vulnerability.
Affected products
- Linux Linux kernel versions with sched_ext implementation
Timeline
- 2026-08-10: disclosed: CVE-2026-68094 published
- 2026-08-10: patched: Fix introduces switch_rq_lock() for consistent rq state tracking