Description
In the Linux kernel, the following vulnerability has been resolved:

cgroup/cpuset: Make nr_deadline_tasks an atomic_t

The nr_deadline_tasks variable in the cpuset structure was introduced by
commit 6c24849f5515 ("sched/cpuset: Keep track of SCHED_DEADLINE task
in cpusets"). It is reported by sashiko [1] that nr_deadline_tasks
can currently be modified by inc_dl_tasks_cs() under rq->lock and
by cpuset_attach() under cpuset_mutex. So if both updates happen
simultaneously, the nr_deadline_tasks variable can be corrupted leading
to incorrect operations down the road.

Fix that by changing its type to atomic_t so that nr_deadline_tasks
are always atomically updated. This fix patch is a low hanging fruit.
It can handle some of the races between a concurrent sched_setscheduler()
and cpuset_can_attach()/cpuset_attach() calls, but not all of them like
the other issue raised by sashiko [2]. This will be handled hopefully
in a future follow up patch.

[1] https://sashiko.dev/#/patchset/20260626181923.133658-1-longman%40redhat.com
[2] https://sashiko.dev/#/patchset/20260630033344.352702-1-longman%40redhat.com
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Race condition that can corrupt task counters
Action: Apply patch
AI Analysis

Impact

The Linux kernel cpuset subsystem maintains a counter of SCHED_DEADLINE tasks. A race condition exists between updates performed by inc_dl_tasks_cs() under the rq->lock and by cpuset_attach() under the cpuset_mutex. When both operations occur simultaneously, the counter can become corrupted, causing incorrect bookkeeping and potentially leading to faulty scheduling or cpuset management. The flaw may enable an attacker to influence task placement or resource allocation, which could affect system stability or performance.

Affected Systems

All Linux kernel releases that implement the cpuset subsystem with the nr_deadline_tasks counter are vulnerable. The vulnerable code path exists before the atomic_t change was introduced. Linux distributions shipping the legacy kernel should verify if the commit that changes the counter to atomic_t is included; if not, the system remains affected.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The patch mitigates some race windows but does not eliminate all concurrency issues, so the overall severity remains uncertain. Successful exploitation would require an attacker to orchestrate concurrent scheduler updates and cpuset attachments in the same kernel context.

Generated by OpenCVE AI on September 19, 2026 at 08:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the atomic_t change for nr_deadline_tasks (commit 6c24849f5515 and subsequent patches).
  • Verify the running kernel contains the atomic_t change—e.g., by checking the source code or using tools that display kernel configuration options. If the current kernel is older, apply the patch manually to the source tree.
  • Modify application logic to serialise calls that alter cpusets and change SCHED_DEADLINE scheduling simultaneously, ensuring they do not execute in parallel on the same CPU set.

Generated by OpenCVE AI on September 19, 2026 at 08:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: Make nr_deadline_tasks an atomic_t The nr_deadline_tasks variable in the cpuset structure was introduced by commit 6c24849f5515 ("sched/cpuset: Keep track of SCHED_DEADLINE task in cpusets"). It is reported by sashiko [1] that nr_deadline_tasks can currently be modified by inc_dl_tasks_cs() under rq->lock and by cpuset_attach() under cpuset_mutex. So if both updates happen simultaneously, the nr_deadline_tasks variable can be corrupted leading to incorrect operations down the road. Fix that by changing its type to atomic_t so that nr_deadline_tasks are always atomically updated. This fix patch is a low hanging fruit. It can handle some of the races between a concurrent sched_setscheduler() and cpuset_can_attach()/cpuset_attach() calls, but not all of them like the other issue raised by sashiko [2]. This will be handled hopefully in a future follow up patch. [1] https://sashiko.dev/#/patchset/20260626181923.133658-1-longman%40redhat.com [2] https://sashiko.dev/#/patchset/20260630033344.352702-1-longman%40redhat.com
Title cgroup/cpuset: Make nr_deadline_tasks an atomic_t
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:46.799Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93150

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:10.213

Modified: 2026-09-17T17:18:10.213

Link: CVE-2026-93150

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T17:00:11Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')