Impact
The Linux kernel scheduling subsystem contains a flaw where the runqueue returned by this_rq() is assumed to match the runqueue of a dispatched CPU. When dispatch scheduler functions may acquire runqueue locks in the wrong order, causing a deadlock. This can stall the scheduler and render the system unable to schedule new tasks, resulting in a denial of Service condition. The weakness is classified as CWE-833.
Affected Systems
All systems running the Linux kernel without the security update that incorporates commit hashes 3dd52416e44a70bc993adb96d2e0d71b9ea21359 and 6d1890d3c6137ab523799765ae2de62cc05f116d are affected. This includes mainstream distributions, embedded platforms, and any custom kernel build that predates these commits.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity. The EPSS score of < 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV‑level privileges or the ability to influence scheduling behavior, as the issue involves internal scheduler lock ordering and dispatcher operations. No public exploits are known, and the EPSS indicates a very low likelihood of exploitation. The likely attack vector would involve manipulating scheduling behavior from privileged context, potentially through a malicious kernel module or other privileged code.
OpenCVE Enrichment