Impact
In the Linux kernel, a flaw in the core scheduling routine causes the pick_next_task() function to behave incorrectly when a custom pick_task() implementation releases the rq lock. Because the selection state is only valid while the lock is held, an interleaving selection after the lock is released can invalidate the entire scheduling decision, leading to tasks being dispatched incorrectly or kernel variables such as force in pick_task(), classified under CWE-367.
Affected Systems
The affected product is the Linux Kernel. The advisory does not list specific kernel versions, so all implementations of the Linux Kernel that expose the described scheduling path may be impacted until the fix is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 7.3, indicating high severity. The EPSS score is very low (< 1%) and it is not listed in the CISA KEV catalog. The bug requires kernel code execution, so the most likely attack vector is local or requires elevated privileges. Because the flaw impacts internal scheduling decisions, an attacker with the ability to influence task scheduling could destabilize the system, potentially leading to performance degradation or denial of service. No publicly available exploits are currently documented, but the high severity and the potential for system instability warrant prompt attention.
OpenCVE Enrichment