Description
In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users

scx_bpf_dsq_reenq() queues a deferred reenq (dru) that runs from
run_deferred(), not ops.dispatch(). If the DSQ is destroyed before the dru
runs, process_deferred_reenq_users() sees dsq->id == SCX_DSQ_INVALID and
hits the BUG_ON. destroy_dsq() doesn't flush pending drus, so just skip.

tj: Read dsq->id once with READ_ONCE(). Reading it separately in the INVALID
check and the BUG_ON would leave a window where destroy_dsq() can
invalidate the id between the two reads and still trigger the BUG_ON.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash (Denial of Service)
Action: Apply Patch
AI Analysis

Impact

A flaw in the Linux kernel’s scx_bpf_dsq subsystem causes a BUG_ON when a deferred reenqueuing (dru) operation runs on a DSQ that has already been destroyed. The kernel checks the DSQ identifier, sees it marked as invalid, and panics. This local denial‑of‑service is categorized as CWE‑825. The crash prevents the operating system from continuing to run until a reboot or kernel reload occurs.

Affected Systems

All Linux kernel versions prior to the published patch are affected. The vulnerability exists in the core kernel; it is not limited to a specific distribution or kernel release. Any system running an unpatched kernel can be impacted, regardless of distribution.

Risk and Exploitability

The CVSS score of 4.1 marks the vulnerability as moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the description, it is inferred that the attack vector requires local or privileged access to manipulate DSQ objects so that destruction precedes the deferred reenqueuing; success would lead to a kernel panic and require a reboot.

Generated by OpenCVE AI on September 15, 2026 at 22:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Linux kernel patch that corrects the DSQ handling bug.
  • Reboot the system after the kernel upgrade.
  • Disable or uninstall any third‑party kernel modules or drivers that interact with DSQ queues until the patch is applied so they do not cause premature DSQ destruction.

Generated by OpenCVE AI on September 15, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users scx_bpf_dsq_reenq() queues a deferred reenq (dru) that runs from run_deferred(), not ops.dispatch(). If the DSQ is destroyed before the dru runs, process_deferred_reenq_users() sees dsq->id == SCX_DSQ_INVALID and hits the BUG_ON. destroy_dsq() doesn't flush pending drus, so just skip. tj: Read dsq->id once with READ_ONCE(). Reading it separately in the INVALID check and the BUG_ON would leave a window where destroy_dsq() can invalidate the id between the two reads and still trigger the BUG_ON.
Title sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:43:59.941Z

Reserved: 2026-09-11T19:38:34.717Z

Link: CVE-2026-89516

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:34.170

Modified: 2026-09-11T20:19:34.170

Link: CVE-2026-89516

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:43:59Z

Links: CVE-2026-89516 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:30:15Z

Weaknesses
  • CWE-825

    Expired Pointer Dereference