Description
In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Abort directly from the hardlockup handler

scx_hardlockup() defers the abort to an irq_work because exit claiming used
to take scx_sched_lock and couldn't run from NMI. The deferral is now
unnecessary - claiming is NMI-safe and asserting ->aborting is exactly what
breaks the live-locks that hard-lock CPUs. Call handle_lockup() directly and
drop the irq_work. This also makes the self-detected case recoverable: the
perf watchdog fires on the hard-locked CPU itself, where a queued irq_work
never runs with IRQs off.

Also fix the return value: %true used to be returned whenever sched_ext was
loaded, suppressing the kernel's hardlockup report even when the abort was
refused. Return %true only when this call initiated the abort.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash / Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel bug caused the hardlockup handler to defer the abort to an irq_work rather than invoking the abort directly, which meant the abort never ran and hard‑locked CPUs could not recover. Additionally, the handler incorrectly returned true on all loads, suppressing hardlockup reports even when aborts were refused. The result is a system‑wide lockup that can lead to permanent CPU failure and loss of services.

Affected Systems

The vulnerability affects the Linux kernel across all vendor distributions that include the sched_ext patch set. No specific version range is listed in the data, so any recent or current kernel that implements the current hardlockup handling code is potentially impacted.

Risk and Exploitability

The EPSS score is indicated as <1%, meaning the likelihood of the flaw being exploited in the wild at this time is very low. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would need to trigger a hard‑lockup condition or exploit a hardware fault to cause the malfunction, as remote code execution is not available. If successful, the impact would be a denial of service via CPU lockup. The overall risk is moderate to low weighted by the low exploitation probability, but the severity of the outcome warrants immediate attention.

Generated by OpenCVE AI on September 19, 2026 at 12:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to a kernel version that incorporates the hardlockup handler fix.
  • If a kernel update is not immediately available, apply the code change from the referenced commits (https://git.kernel.org/stable/c/3c4b38064937a761ebbf85b1649e812db85eb59e and https://git.kernel.org/stable/c/4d6270bbb4e083a4d2d39f3c36f30f5c939c06ed).
  • Disable or remove the problematic sched_ext feature if possible, or adjust kernel configuration to avoid triggering the hardlockup path.
  • Apply standard kernel hard‑lockup monitoring and alerting to detect any unrecoverable CPU locks promptly.

Generated by OpenCVE AI on September 19, 2026 at 12:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-398
CWE-753

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: sched_ext: Abort directly from the hardlockup handler scx_hardlockup() defers the abort to an irq_work because exit claiming used to take scx_sched_lock and couldn't run from NMI. The deferral is now unnecessary - claiming is NMI-safe and asserting ->aborting is exactly what breaks the live-locks that hard-lock CPUs. Call handle_lockup() directly and drop the irq_work. This also makes the self-detected case recoverable: the perf watchdog fires on the hard-locked CPU itself, where a queued irq_work never runs with IRQs off. Also fix the return value: %true used to be returned whenever sched_ext was loaded, suppressing the kernel's hardlockup report even when the abort was refused. Return %true only when this call initiated the abort.
Title sched_ext: Abort directly from the hardlockup handler
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:52.429Z

Reserved: 2026-09-11T19:38:34.815Z

Link: CVE-2026-90432

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:48.263

Modified: 2026-09-17T17:17:48.263

Link: CVE-2026-90432

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:45:17Z

Weaknesses