CVE-2026-89519: sched_ext: Replace SCX_RQ_BAL_KEEP with a dispatch verdict return
In the Linux kernel, the following vulnerability has been resolved:
schedext: Replace SCXRQBALKEEP with a dispatch verdict return
SCXRQBALKEEP tells the pick to keep running the previous task, a leftover from when balancing and picking were separate operations. An rq-level flag only works while dispatches and picks pair up one to one, which core scheduling breaks: selections interleave through dispatch's lock drops and a pick can consume a stale flag, keeping a task that has since been dequeued. Fixing core scheduling support requires the decision to travel with the dispatch that made it. Make scxdispatchsched() and balanceone() return an explicit verdict instead and drop the flag's plumbing from the tools autogen enum headers.
Also factor the pick-side invocation, its follow-up queueing and the post-dispatch checks out of dopicktaskscx() into dispatchpick(). No functional changes intended.
v2: Drop the SCXRQBALKEEP plumbing from the tools autogen enum headers as well (Andrea).
Event History
Frequently Asked Questions
Are functional scheduling changes expected after applying the fix?
No functional changes are intended. The change replaces an rq-level keep-running flag with an explicit dispatch verdict so the decision remains associated with the dispatch that made it.
What else must be updated when backporting this fix?
The SCX_RQ_BAL_KEEP plumbing must also be removed from the tools autogenerated enum headers. The referenced stable commits contain the corresponding changes.