Description
In the Linux kernel, the following vulnerability has been resolved:

sched/fair: Fix overflow in update_tg_cfs_runnable()

A divide-by-zero crash is observed when running hackbench:

[14697.488452] CPU: 112 UID: 0 PID: 124791 Comm: hackbench Not tainted 7.1.0-rc2+
[14697.492627] RIP: 0010:propagate_entity_load_avg+0x35f/0x3e0
[14697.506799] <TASK>
[14697.507411] __dequeue_task+0x2b4/0xc70
[14697.508677] dequeue_task_fair+0x36/0x370
[14697.509047] dequeue_task+0x101/0x2f0
[14697.509426] __schedule+0x1b1/0x1a00
[14697.510868] anon_pipe_read+0x3da/0x450
[14697.511400] vfs_read+0x361/0x390
[14697.512053] __x64_sys_read+0x19/0x30

The divide-by-zero happens here:

if (scale_load_down(gcfs_rq->load.weight)) {
load_sum = div_u64(gcfs_rq->avg.load_sum,
scale_load_down(gcfs_rq->load.weight));
}

gcfs_rq->load.weight is an insane large value and is truncated
to the lower 32 bits by div_u64, which happen to be 0.

Using AI for investigation, the cause is a u32 overflow in
update_tg_cfs_runnable(), and flat pickup became a victim when using
tg_tasks():

u32 new_sum, divider;
...
new_sum = se->avg.runnable_avg * divider; <-- boom

The following sequence shows how this triggers the crash:

propagate_entity_load_avg()
update_tg_cfs_runnable() # u32 overflow corrupts runnable_sum

__update_load_avg_cfs_rq()
___update_load_avg() # computes insane runnable_avg
update_tg_load_avg() # propagates to tg->runnable_avg

update_cfs_group()
calc_concur_shares()
tg_tasks() # long-to-int truncation, negative nr
reweight_entity() # corrupted se->load.weight
update_load_add() # corrupted cfs_rq->load.weight

propagate_entity_load_avg()
update_tg_cfs_load()
div_u64() # divide-by-zero

Fix by widening new_sum from u32 to u64 (no need to force tg_tasks()
to return unsigned long after this fix)
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash (divide‑by‑zero)
Action: Apply Patch
AI Analysis

Impact

The Linux kernel contains a bug in the fair scheduler where an unsigned 32‑bit overflow in update_tg_cfs_runnable() corrupts the runnable‐average calculation. This overflow causes a divide‑by‑zero in propagate_entity_load_avg(), resulting in a kernel panic. When this crash occurs the operating system becomes unavailable, effectively delivering a denial‑of‑service condition. The vulnerability is triggered by specific task scheduling scenarios and does not directly allow arbitrary code execution, but the loss of a running kernel is a critical impact for any host.

Affected Systems

The flaw exists in the Linux kernel across all distributions that ship the kernel source unchanged. No exact product version range is listed in the advisory; the vulnerability was fixed by committing changes in the 7.1.0‑rc2 branch and subsequent stable releases. Systems running any pre‑patch kernel are potentially affected and should check the vendor’s kernel changelog for the resolution commit references provided in the advisory.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating that public exploitation is not common or widely observed. The flaw is not listed in CISA’s KEV catalog. Because the bug manifests as a kernel panic, it is highly disruptive if achieved but requires privileged or local access to manipulate scheduling in the exact manner that triggers the overflow. In environments where kernel uptime is critical, the risk of unplanned downtime is significant despite the low likelihood of exploitation.

Generated by OpenCVE AI on September 19, 2026 at 08:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the fix introduced by the commits referenced (e.g., the 7.1.0‑rc2 and later releases that contain the patch to widen the u32 overflow to u64 in update_tg_cfs_runnable()).
  • If an immediate upgrade is not possible, apply the patch manually to the kernel source or build a custom kernel that includes the commit that fixes the overflow.
  • After applying the patch or upgrading, monitor system logs for any remaining scheduling anomalies and verify that the kernel no longer crashes under high load conditions.

Generated by OpenCVE AI on September 19, 2026 at 08:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-369
CWE-680

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix overflow in update_tg_cfs_runnable() A divide-by-zero crash is observed when running hackbench: [14697.488452] CPU: 112 UID: 0 PID: 124791 Comm: hackbench Not tainted 7.1.0-rc2+ [14697.492627] RIP: 0010:propagate_entity_load_avg+0x35f/0x3e0 [14697.506799] <TASK> [14697.507411] __dequeue_task+0x2b4/0xc70 [14697.508677] dequeue_task_fair+0x36/0x370 [14697.509047] dequeue_task+0x101/0x2f0 [14697.509426] __schedule+0x1b1/0x1a00 [14697.510868] anon_pipe_read+0x3da/0x450 [14697.511400] vfs_read+0x361/0x390 [14697.512053] __x64_sys_read+0x19/0x30 The divide-by-zero happens here: if (scale_load_down(gcfs_rq->load.weight)) { load_sum = div_u64(gcfs_rq->avg.load_sum, scale_load_down(gcfs_rq->load.weight)); } gcfs_rq->load.weight is an insane large value and is truncated to the lower 32 bits by div_u64, which happen to be 0. Using AI for investigation, the cause is a u32 overflow in update_tg_cfs_runnable(), and flat pickup became a victim when using tg_tasks(): u32 new_sum, divider; ... new_sum = se->avg.runnable_avg * divider; <-- boom The following sequence shows how this triggers the crash: propagate_entity_load_avg() update_tg_cfs_runnable() # u32 overflow corrupts runnable_sum __update_load_avg_cfs_rq() ___update_load_avg() # computes insane runnable_avg update_tg_load_avg() # propagates to tg->runnable_avg update_cfs_group() calc_concur_shares() tg_tasks() # long-to-int truncation, negative nr reweight_entity() # corrupted se->load.weight update_load_add() # corrupted cfs_rq->load.weight propagate_entity_load_avg() update_tg_cfs_load() div_u64() # divide-by-zero Fix by widening new_sum from u32 to u64 (no need to force tg_tasks() to return unsigned long after this fix)
Title sched/fair: Fix overflow in update_tg_cfs_runnable()
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:09.381Z

Reserved: 2026-09-17T16:02:15.091Z

Link: CVE-2026-93182

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:14.153

Modified: 2026-09-17T17:18:14.153

Link: CVE-2026-93182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:45:17Z

Weaknesses