Impact
The Linux kernel contains a bug in the fair scheduler where an unsigned 32‑bit overflow in update_tg_cfs_runnable() corrupts the runnable‐average calculation. This overflow causes a divide‑by‑zero in propagate_entity_load_avg(), resulting in a kernel panic. When this crash occurs the operating system becomes unavailable, effectively delivering a denial‑of‑service condition. The vulnerability is triggered by specific task scheduling scenarios and does not directly allow arbitrary code execution, but the loss of a running kernel is a critical impact for any host.
Affected Systems
The flaw exists in the Linux kernel across all distributions that ship the kernel source unchanged. No exact product version range is listed in the advisory; the vulnerability was fixed by committing changes in the 7.1.0‑rc2 branch and subsequent stable releases. Systems running any pre‑patch kernel are potentially affected and should check the vendor’s kernel changelog for the resolution commit references provided in the advisory.
Risk and Exploitability
The EPSS score is reported as less than 1 %, indicating that public exploitation is not common or widely observed. The flaw is not listed in CISA’s KEV catalog. Because the bug manifests as a kernel panic, it is highly disruptive if achieved but requires privileged or local access to manipulate scheduling in the exact manner that triggers the overflow. In environments where kernel uptime is critical, the risk of unplanned downtime is significant despite the low likelihood of exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA