Impact
The Linux kernel bug involves the obsolete SCX_RQ_BAL_KEEP flag, which caused older scheduling code to continue running a task after it had been dequeued. Replacing the flag with an explicit dispatch verdict return eliminates a race between dispatch and pick operations, restoring correct task selection behavior. The flaw is a scheduling error that could lead to mis‑directed CPU time but does not expose secrets or provide direct code‑execution.
Affected Systems
All Linux kernel releases that contain the flag before the commit that removes it are affected. The patch is integrated into kernel versions released after that commit, so any distribution kernel earlier than that point remains vulnerable until upgraded.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity. The EPSS score is less than 1%, implying a very low probability of exploitation, and the vulnerability is not catalogued in CISA’s KEV list. Successful exploitation would require an attacker to run code with kernel privileges to trigger the scheduling race; no publicly documented exploits exist.
OpenCVE Enrichment