From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A7D22584968 for ; Fri, 11 Sep 2026 19:55:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156562; cv=none; b=GjIYXB70R5U8UuTrrFOk5LMQfl+LhJkba1JMkb480weP58FsYtNkpAJuiH2SQWhzVw8DeqnU5udc7hELnvqJYTRvHk7/ijODetyRXGCvJNL62BFna4XKKB9VUFyC45VzXq+x6bBG57uMthHMUZTGFDdzQP+FWzwu89yrl0mRCPc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156562; c=relaxed/simple; bh=tWg7YFPotFlOsaRj3CFoHyJfamKlOSQXQIhKt04In6c=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Z4+HnZT+1E41rAQ2Vj4aeWORKdZL7mm8gjsVW+Yx39ExiOLYGCgX3/0K09WR3cAJGoCD+O5/29kcHAfb/IdW6X63bAvxlXE6K+x3z6X6j3LuCETigih28a6EGiR5wu0Ho+jIIpckW0DqvRATC7sDKlZGBRTQmEYB+qywS51P0/Y= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=lvwDiEEq; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="lvwDiEEq" Received: by smtp.kernel.org (Postfix) with ESMTPSA id AD69F1F00893; Fri, 11 Sep 2026 19:55:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156550; bh=yPQAuoKsp5MiJQA2z+tHBIjPJw2+7EDouq6atcwEObA=; h=From:To:Cc:Subject:Date:Reply-To; b=lvwDiEEqIYbf0iQV+VpYPdrkcFrCa05MEWHJt4iOUuHZUZrCa9x2fqYDGJpRn0NCP PgPJQr76kLyFJQBczNfQlsKAzOVZ+ARgsG8ZDbjI2i1mFvI4Eg6krNI33h5QaR8UEm ekINeUJ7OLWN7gB1thV0xpXTXtdmY0r6tkvBiBmc= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-89520: sched/core: Make core-sched flips wait for in-flight selections Date: Fri, 11 Sep 2026 21:43:29 +0200 Message-ID: <2026091114-CVE-2026-89520-a47c@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3045; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=F4jBi6pbB0Xlg/NVOgvLX1Bu9KuVIdvRS2yWFjA1hr0=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIqPy9s9YsWRpTPPc6Sricd8cixWXvZL2N+etjLE/U tZa9utERywLgyATg6yYIsuXbTxH91ccUvQytD0NM4eVCWQIAxenAExk10eGBVNKtYwF/M+Z1axg PbbDKcXt6aZPzxhms7lyKkxrDZuY8N2j6w67Wm6Ia14dAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: sched/core: Make core-sched flips wait for in-flight selections Core scheduling's pick_next_task() operates on all sibling rqs under one acquisition of the shared core-wide lock. A ->pick_task() that releases the rq lock leaves every sibling __lock momentarily free, letting __sched_core_flip(false) complete mid-selection and rebind rq_lockp() under it. The selection resumes on the split locks, touching sibling state it no longer protects, and __schedule() finally releases a lock that was never taken while leaking the one that was. Count in-flight core-wide selections in the leader's rq->core_pick_in_flight and make __sched_core_flip() wait for the count to drain. The count only changes under the shared lock, which the flip holds while sampling, so no other ordering is needed. The wait can repeat while selections overlap, but the flip backs off between samples and flips are rare cookie-lifetime events. sched_core_cpu_deactivate() moves the count to the new leader - a stale copy left behind would bias it forever if that CPU later returns as its own leader. The Linux kernel CVE team has assigned CVE-2026-89520 to this issue. Affected and fixed versions =========================== Issue introduced in 5.14 with commit 539f65125d20aacab54d02d77f10a839f45b09dc and fixed in 6.18.51 with commit 9d69422ddaa13526c2223444e237d948d6e44728 Issue introduced in 5.14 with commit 539f65125d20aacab54d02d77f10a839f45b09dc and fixed in 7.2.4 with commit 23eda24f325a6e6d686d30ec75f2e9d6745e2015 Issue introduced in 5.14 with commit 539f65125d20aacab54d02d77f10a839f45b09dc and fixed in 7.3-rc1 with commit f3629c63a4af3e491381780bc6c123cb498c4c40 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-89520 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: kernel/sched/core.c kernel/sched/sched.h Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/9d69422ddaa13526c2223444e237d948d6e44728 https://git.kernel.org/stable/c/23eda24f325a6e6d686d30ec75f2e9d6745e2015 https://git.kernel.org/stable/c/f3629c63a4af3e491381780bc6c123cb498c4c40