{"api_version":"1","generated_at":"2026-08-12T13:44:52+00:00","cve":"CVE-2026-68094","urls":{"html":"https://cve.report/CVE-2026-68094","api":"https://cve.report/api/cve/CVE-2026-68094.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-68094","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-68094"},"summary":{"title":"sched_ext: Preserve rq tracking across local DSQ dispatch","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Preserve rq tracking across local DSQ dispatch\n\ndispatch_to_local_dsq() can run from scx_bpf_dsq_move_to_local() while\nops.dispatch() has recorded the current rq. Moving a task to a local DSQ\nmay switch to the source or destination rq before synchronously invoking\nops.dequeue() through the following path:\n\n  SCX_CALL_OP(dispatch, rq)\n    ops.dispatch()\n      scx_bpf_dsq_move_to_local()\n        scx_flush_dispatch_buf()\n          finish_dispatch()\n            dispatch_to_local_dsq()\n              scx_dispatch_enqueue()\n                local_dsq_post_enq()\n                  call_task_dequeue()\n                    SCX_CALL_OP_TASK(dequeue, locked_rq, ...)\n\nThe nested callback saves the recorded rq and restores it on return. If\nthe rq tracking does not follow the lock switch, update_locked_rq() can\ntrigger the following lockdep assertion while restoring an rq which is\nno longer held:\n\n  WARNING: kernel/sched/sched.h:1641 at call_task_dequeue+0x160/0x170\n  Call Trace:\n    scx_dispatch_enqueue+0x2b0/0x460\n    dispatch_to_local_dsq+0x138/0x230\n    scx_flush_dispatch_buf+0x1af/0x220\n    scx_bpf_dsq_move_to_local___v2+0xe2/0x1c0\n    bpf__sched_ext_ops_dispatch+0x4b/0xa7\n    do_pick_task_scx+0x3b6/0x910\n    __pick_next_task+0x105/0x1f0\n    __schedule+0x3e7/0x1980\n\nIntroduce switch_rq_lock() to update the tracking state together with\neach rq lock handoff. Use it in dispatch_to_local_dsq(),\nmove_remote_task_to_local_dsq() and the in-balance paths of\nscx_dsq_move(), ensuring that scx_locked_rq() consistently refers to the\nrq whose lock is actually held throughout the lock dance.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-10 13:19:53","updated_at":"2026-08-10 13:19:53"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/97c09c9f5739b8757ee29dabb0af30069137e286","name":"https://git.kernel.org/stable/c/97c09c9f5739b8757ee29dabb0af30069137e286","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/18d62044cda7a2b40f59d910659c0b0d6accad37","name":"https://git.kernel.org/stable/c/18d62044cda7a2b40f59d910659c0b0d6accad37","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68094","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68094","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7fb39e4eb4c3db52e4707a6a1cd45362f7e803f5 97c09c9f5739b8757ee29dabb0af30069137e286 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7fb39e4eb4c3db52e4707a6a1cd45362f7e803f5 18d62044cda7a2b40f59d910659c0b0d6accad37 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 7.1","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.6 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc4 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["kernel/sched/ext/ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"97c09c9f5739b8757ee29dabb0af30069137e286","status":"affected","version":"7fb39e4eb4c3db52e4707a6a1cd45362f7e803f5","versionType":"git"},{"lessThan":"18d62044cda7a2b40f59d910659c0b0d6accad37","status":"affected","version":"7fb39e4eb4c3db52e4707a6a1cd45362f7e803f5","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["kernel/sched/ext/ext.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"7.1"},{"lessThan":"7.1","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc4","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.6","versionStartIncluding":"7.1","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc4","versionStartIncluding":"7.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Preserve rq tracking across local DSQ dispatch\n\ndispatch_to_local_dsq() can run from scx_bpf_dsq_move_to_local() while\nops.dispatch() has recorded the current rq. Moving a task to a local DSQ\nmay switch to the source or destination rq before synchronously invoking\nops.dequeue() through the following path:\n\n  SCX_CALL_OP(dispatch, rq)\n    ops.dispatch()\n      scx_bpf_dsq_move_to_local()\n        scx_flush_dispatch_buf()\n          finish_dispatch()\n            dispatch_to_local_dsq()\n              scx_dispatch_enqueue()\n                local_dsq_post_enq()\n                  call_task_dequeue()\n                    SCX_CALL_OP_TASK(dequeue, locked_rq, ...)\n\nThe nested callback saves the recorded rq and restores it on return. If\nthe rq tracking does not follow the lock switch, update_locked_rq() can\ntrigger the following lockdep assertion while restoring an rq which is\nno longer held:\n\n  WARNING: kernel/sched/sched.h:1641 at call_task_dequeue+0x160/0x170\n  Call Trace:\n    scx_dispatch_enqueue+0x2b0/0x460\n    dispatch_to_local_dsq+0x138/0x230\n    scx_flush_dispatch_buf+0x1af/0x220\n    scx_bpf_dsq_move_to_local___v2+0xe2/0x1c0\n    bpf__sched_ext_ops_dispatch+0x4b/0xa7\n    do_pick_task_scx+0x3b6/0x910\n    __pick_next_task+0x105/0x1f0\n    __schedule+0x3e7/0x1980\n\nIntroduce switch_rq_lock() to update the tracking state together with\neach rq lock handoff. Use it in dispatch_to_local_dsq(),\nmove_remote_task_to_local_dsq() and the in-balance paths of\nscx_dsq_move(), ensuring that scx_locked_rq() consistently refers to the\nrq whose lock is actually held throughout the lock dance."}],"providerMetadata":{"dateUpdated":"2026-08-10T11:58:07.086Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/97c09c9f5739b8757ee29dabb0af30069137e286"},{"url":"https://git.kernel.org/stable/c/18d62044cda7a2b40f59d910659c0b0d6accad37"}],"title":"sched_ext: Preserve rq tracking across local DSQ dispatch","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-68094","datePublished":"2026-08-10T11:58:07.086Z","dateReserved":"2026-07-30T09:28:09.367Z","dateUpdated":"2026-08-10T11:58:07.086Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 13:19:53","lastModifiedDate":"2026-08-10 13:19:53","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"68094","Ordinal":"1","Title":"sched_ext: Preserve rq tracking across local DSQ dispatch","CVE":"CVE-2026-68094","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"68094","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Preserve rq tracking across local DSQ dispatch\n\ndispatch_to_local_dsq() can run from scx_bpf_dsq_move_to_local() while\nops.dispatch() has recorded the current rq. Moving a task to a local DSQ\nmay switch to the source or destination rq before synchronously invoking\nops.dequeue() through the following path:\n\n  SCX_CALL_OP(dispatch, rq)\n    ops.dispatch()\n      scx_bpf_dsq_move_to_local()\n        scx_flush_dispatch_buf()\n          finish_dispatch()\n            dispatch_to_local_dsq()\n              scx_dispatch_enqueue()\n                local_dsq_post_enq()\n                  call_task_dequeue()\n                    SCX_CALL_OP_TASK(dequeue, locked_rq, ...)\n\nThe nested callback saves the recorded rq and restores it on return. If\nthe rq tracking does not follow the lock switch, update_locked_rq() can\ntrigger the following lockdep assertion while restoring an rq which is\nno longer held:\n\n  WARNING: kernel/sched/sched.h:1641 at call_task_dequeue+0x160/0x170\n  Call Trace:\n    scx_dispatch_enqueue+0x2b0/0x460\n    dispatch_to_local_dsq+0x138/0x230\n    scx_flush_dispatch_buf+0x1af/0x220\n    scx_bpf_dsq_move_to_local___v2+0xe2/0x1c0\n    bpf__sched_ext_ops_dispatch+0x4b/0xa7\n    do_pick_task_scx+0x3b6/0x910\n    __pick_next_task+0x105/0x1f0\n    __schedule+0x3e7/0x1980\n\nIntroduce switch_rq_lock() to update the tracking state together with\neach rq lock handoff. Use it in dispatch_to_local_dsq(),\nmove_remote_task_to_local_dsq() and the in-balance paths of\nscx_dsq_move(), ensuring that scx_locked_rq() consistently refers to the\nrq whose lock is actually held throughout the lock dance.","Type":"Description","Title":"sched_ext: Preserve rq tracking across local DSQ dispatch"}]}}}