Impact
The Linux kernel cpuset subsystem maintains a counter of SCHED_DEADLINE tasks. A race condition exists between updates performed by inc_dl_tasks_cs() under the rq->lock and by cpuset_attach() under the cpuset_mutex. When both operations occur simultaneously, the counter can become corrupted, causing incorrect bookkeeping and potentially leading to faulty scheduling or cpuset management. The flaw may enable an attacker to influence task placement or resource allocation, which could affect system stability or performance.
Affected Systems
All Linux kernel releases that implement the cpuset subsystem with the nr_deadline_tasks counter are vulnerable. The vulnerable code path exists before the atomic_t change was introduced. Linux distributions shipping the legacy kernel should verify if the commit that changes the counter to atomic_t is included; if not, the system remains affected.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The patch mitigates some race windows but does not eliminate all concurrency issues, so the overall severity remains uncertain. Successful exploitation would require an attacker to orchestrate concurrent scheduler updates and cpuset attachments in the same kernel context.
OpenCVE Enrichment
Debian DLA
Debian DSA