PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43392 Linux CVE debrief

A vulnerability in the Linux kernel's sched_ext (BPF extensible scheduler) subsystem allows system hangs during scheduler enablement. When scx_enable() executes, it transitions tasks from the fair scheduling class to the ext class. Because fair class tasks have higher priority than ext class tasks, a saturated fair-class workload can indefinitely starve the enable thread, causing a complete system hang. The issue was introduced when the enable path switched from preempt_disable() to scx_bypass(), which lacks protection against fair-class starvation. The fix offloads the enable operation to a dedicated system-wide RT (SCHED_FIFO) kthread that cannot be starved by either fair or ext class tasks.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-08
Original CVE updated
2026-05-26
Advisory published
2026-05-08
Advisory updated
2026-05-26

Who should care

Organizations running Linux kernels with sched_ext enabled, particularly those using BPF-based extensible schedulers in production environments. System administrators managing container orchestration platforms or high-density compute environments where scheduler enablement may occur under load. Security teams tracking local denial-of-service vectors in kernel subsystems.

Technical summary

The sched_ext subsystem in the Linux kernel contains a race condition where scx_enable() can be starved by fair-class workloads. The enable path transitions tasks from fair to ext scheduling class, but because fair has higher priority, saturated fair workloads block completion. The vulnerability exists because scx_bypass() does not protect against fair-class starvation, unlike the previous preempt_disable() approach. The resolution creates a dedicated SCHED_FIFO kthread with real-time priority that executes the enable body, ensuring it cannot be starved by either fair or ext class tasks. The kthread is lazily initialized and uses kthread_work for synchronous completion handling.

Defensive priority

medium

Recommended defensive actions

  • Apply kernel patches from the stable kernel git repository to affected systems
  • Upgrade to Linux kernel 6.12.78 or later for 6.12.x series
  • Upgrade to Linux kernel 6.18.20 or later for 6.13-6.18.x series
  • Upgrade to Linux kernel 6.19.9 or later for 6.19.x series
  • Monitor systems using sched_ext for unexpected hangs during scheduler enablement
  • Review BPF scheduler loading procedures for potential trigger conditions

Evidence notes

The vulnerability affects Linux kernel versions 6.12 through 6.19.9, including release candidates. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) indicates local attack vector with low attack complexity, requiring low privileges, resulting in high availability impact. The fix involves creating a dedicated RT kthread for the enable operation and using kthread_work for synchronization.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43392 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43392

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43392 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43392

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/05ab9ec5dc24f234e0a2fecf3e6ff937c68f7d81

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b06ccbabe2506fd70b9167a644978b049150224a

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c44198f25fdfecc0ec0fe366bf8a47fe17d8e229

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e0b14bf06393be137d3efb6a3b7cd5b4b9810a6b

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.