CVE-2026-23371Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting Running stress-ng --schedpolicy 0 on an RT kernel on a big machine might lead to the following WARNINGs (edited). sched: DL de-boosted task PID 22725: REPLENISH flag missing WARNING: CPU: 93 PID: 0 at kernel/sched/deadline.c:239 dequeue_task_dl+0x15c/0x1f8 ... (running_bw underflow) Call trace: dequeue_task_dl+0x15c/0x1f8 (P) dequeue_task+0x80/0x168 deactivate_task+0x24/0x50 push_dl_task+0x264/0x2e0 dl_task_timer+0x1b0/0x228 __hrtimer_run_queues+0x188/0x378 hrtimer_interrupt+0xfc/0x260 ... The problem is that when a SCHED_DEADLINE task (lock holder) is changed to a lower priority class via sched_setscheduler(), it may fail to properly inherit the parameters of potential DEADLINE donors if it didn't already inherit them in the past (shorter deadline than donor's at that time). This might lead to bandwidth accounting corruption, as enqueue_task_dl() won't recognize the lock holder as boosted. The scenario occurs when: 1. A DEADLINE task (donor) blocks on a PI mutex held by another DEADLINE task (holder), but the holder doesn't inherit parameters (e.g., it already has a shorter deadline) 2. sched_setscheduler() changes the holder from DEADLINE to a lower class while still holding the mutex 3. The holder should now inherit DEADLINE parameters from the donor and be enqueued with ENQUEUE_REPLENISH, but this doesn't happen Fix the issue by introducing __setscheduler_dl_pi(), which detects when a DEADLINE (proper or boosted) task gets setscheduled to a lower priority class. In case, the function makes the task inherit DEADLINE parameters of the donoer (pi_se) and sets ENQUEUE_REPLENISH flag to ensure proper bandwidth accounting during the next enqueue operation.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-25); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-25: 1Mentions · 2026-03-26: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 103-2503-26
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-251
Patch1
2026-03-261
General1
Full discourse2 posts
  • WindowsForum@windowsforum
    General

    ⚙️ Nothing says “deadline scheduling” like tripping over bandwidth accounting. Missing ENQUEUE_REPLENISH + PI de-boosting = underflow warnings—because timing is hard, apparently. #WindowsForum https://windowsforum.com/threads/cve-2026-23371-sched_deadline-pi-de-boost-missing-enqueue_replenish-flag.407489/ #LinuxKernel #Cve202623371 #SchedDeadline #PriorityInheritance https://t.co/YzI5K65Mjh

    Post summary

    The post references a Linux scheduler bug (CVE‑2026‑23371) with missing flags causing timing issues, but provides no PoC, exploit, or patch information.

    0000023
    1.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23371 In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting Running stress-ng --schedpol… https://www.cve.org/CVERecord?id=CVE-2026-23371

    Post summary

    The post announces that CVE‑2026‑23371, a Linux kernel scheduler issue, has been fixed with a patch that addresses a missing ENQUEUE_REPLENISH during PI de‑boosting.

    0000087
    56.8K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.10--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more