CVE-2026-23371: sched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting

Published Mar 25, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

sched/deadline: Fix missing ENQUEUEREPLENISH during PI de-boosting

Running stress-ng --schedpolicy 0 on an RT kernel on a big machine might lead to the following WARNINGs (edited).

sched: DL de-boosted task PID 22725: REPLENISH flag missing

WARNING: CPU: 93 PID: 0 at kernel/sched/deadline.c:239 dequeuetaskdl+0x15c/0x1f8 ... (runningbw underflow) Call trace: dequeuetaskdl+0x15c/0x1f8 (P) dequeuetask+0x80/0x168 deactivatetask+0x24/0x50 pushdltask+0x264/0x2e0 dltasktimer+0x1b0/0x228 hrtimerrunqueues+0x188/0x378 hrtimerinterrupt+0xfc/0x260 ...

The problem is that when a SCHEDDEADLINE task (lock holder) is changed to a lower priority class via schedsetscheduler(), it may fail to properly inherit the parameters of potential DEADLINE donors if it didn't already inherit them in the past (shorter deadline than donor's at that time). This might lead to bandwidth accounting corruption, as enqueuetaskdl() won't recognize the lock holder as boosted.

The scenario occurs when: 1. A DEADLINE task (donor) blocks on a PI mutex held by another DEADLINE task (holder), but the holder doesn't inherit parameters (e.g., it already has a shorter deadline) 2. schedsetscheduler() changes the holder from DEADLINE to a lower class while still holding the mutex 3. The holder should now inherit DEADLINE parameters from the donor and be enqueued with ENQUEUEREPLENISH, but this doesn't happen

Fix the issue by introducing setschedulerdlpi(), which detects when a DEADLINE (proper or boosted) task gets setscheduled to a lower priority class. In case, the function makes the task inherit DEADLINE parameters of the donoer (pise) and sets ENQUEUEREPLENISH flag to ensure proper bandwidth accounting during the next enqueue operation.

Affected Software

12 affected components
Linux Linux kernel
Linux Linux kernel>=4.19.257<4.20
Linux Linux kernel>=5.4.212<5.5
Linux Linux kernel>=5.10.1<6.19.7
Linux Linux kernel=5.10
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7

Event History

Mar 25, 2026
CVE Published
via MITRE·10:27 AM
Data Sourced
via MITRE·10:27 AM
Description
Data Sourced
via NVD·11:16 AM
RemedyDescriptionSeverityAffected Software
Mar 26, 2026
Data Sourced
via Microsoft·08:05 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-23371?

CVE-2026-23371 is categorized as a potential high-severity vulnerability affecting the Linux kernel.

2

How do I fix CVE-2026-23371?

To fix CVE-2026-23371, update your Linux kernel to the latest stable version that includes the patch.

3

What systems are affected by CVE-2026-23371?

CVE-2026-23371 affects the Linux kernel, particularly in configurations that involve real-time scheduling.

4

What type of vulnerability is CVE-2026-23371?

CVE-2026-23371 is a scheduling vulnerability in the Linux kernel regarding missing ENQUEUE_REPLENISH during priority inheritance de-boosting.

5

Can CVE-2026-23371 be exploited remotely?

CVE-2026-23371 does not directly indicate remote exploitation vectors; it primarily impacts local processes on systems running affected kernels.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203