Impact
The Linux kernel bug caused the hardlockup handler to defer the abort to an irq_work rather than invoking the abort directly, which meant the abort never ran and hard‑locked CPUs could not recover. Additionally, the handler incorrectly returned true on all loads, suppressing hardlockup reports even when aborts were refused. The result is a system‑wide lockup that can lead to permanent CPU failure and loss of services.
Affected Systems
The vulnerability affects the Linux kernel across all vendor distributions that include the sched_ext patch set. No specific version range is listed in the data, so any recent or current kernel that implements the current hardlockup handling code is potentially impacted.
Risk and Exploitability
The EPSS score is indicated as <1%, meaning the likelihood of the flaw being exploited in the wild at this time is very low. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker would need to trigger a hard‑lockup condition or exploit a hardware fault to cause the malfunction, as remote code execution is not available. If successful, the impact would be a denial of service via CPU lockup. The overall risk is moderate to low weighted by the low exploitation probability, but the severity of the outcome warrants immediate attention.
OpenCVE Enrichment