Impact
A flaw in the Linux kernel’s scx_bpf_dsq subsystem causes a BUG_ON when a deferred reenqueuing (dru) operation runs on a DSQ that has already been destroyed. The kernel checks the DSQ identifier, sees it marked as invalid, and panics. This local denial‑of‑service is categorized as CWE‑825. The crash prevents the operating system from continuing to run until a reboot or kernel reload occurs.
Affected Systems
All Linux kernel versions prior to the published patch are affected. The vulnerability exists in the core kernel; it is not limited to a specific distribution or kernel release. Any system running an unpatched kernel can be impacted, regardless of distribution.
Risk and Exploitability
The CVSS score of 4.1 marks the vulnerability as moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the description, it is inferred that the attack vector requires local or privileged access to manipulate DSQ objects so that destruction precedes the deferred reenqueuing; success would lead to a kernel panic and require a reboot.
OpenCVE Enrichment