Impact
The vulnerability is a race condition in Linux kernel core scheduling that can produce a NULL pointer dereference or a deadlock when two pick_next_task() operations run concurrently on SMT siblings after the core‑wide rq lock is released. This manifests as a kernel crash or hard hang, compromising availability and potentially enabling a reboot loop. The weakness is a classic null pointer dereference, referenced as CWE-476.
Affected Systems
All Linux kernel implementations that have not yet applied the core‑scheduling patch are affected. This includes every generic distribution kernel up to the point of the patch commit and any kernels that do not incorporate that update, regardless of vendor customizations.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.5, indicating moderate severity, while the EPSS score of <1% and absence from the CISA KEV catalog suggest exploitation is unlikely to be widespread. The attack vector is likely local: any process that can generate heavy scheduling traffic may trigger the race. No remote code execution or network interface is involved, so the risk remains moderate until the kernel is patched or the race condition is mitigated.
OpenCVE Enrichment