CVE-2026-93150
In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: Make nr_deadline_tasks an atomic_t The nr_deadline_tasks variable in the cpuset structure was introduced by commit 6c24849f5515 ("sched/cpuset: Keep track of SCHED_DEADLINE task in cpusets"). It is reported by sashiko [1] that nr_deadline_tasks can currently be modified by inc_dl_tasks_cs() under rq->lock and by cpuset_attach() under cpuset_mutex. So if both updates happen simultaneously, the nr_deadline_tasks variable can be corrupted leading to incorrect operations down the road. Fix that by changing its type to atomic_t so that nr_deadline_tasks are always atomically updated. This fix patch is a low hanging fruit. It can handle some of the races between a concurrent sched_setscheduler() and cpuset_can_attach()/cpuset_attach() calls, but not all of them like the other issue raised by sashiko [2]. This will be handled hopefully in a future follow up patch. [1] https://sashiko.dev/#/patchset/20260626181923.133658-1-longman%40redhat.com [2] https://sashiko.dev/#/patchset/20260630033344.352702-1-longman%40redhat.com
Affected versions
Linux kernel versions
5.10.193,
5.15.129,
6.1.50,
6.4.13,
6.5
and later are affected. Fixed in
6.12.110,
6.18.52,
7.2.6,
7.3-rc1
and their respective stable series.
References
4 totalFrequently asked questions
-
What is CVE-2026-93150?
CVE-2026-93150 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.10.193 onward and has been patched in 6.12.110, 6.18.52, 7.2.6 and others. CVE-2026-93150 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-93150?
Yes. CVE-2026-93150 has been patched. Fixed versions include 6.12.110, 6.18.52, 7.2.6 and others. If you are running Linux kernel 5.10.193 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-93150 actively exploited?
No. CVE-2026-93150 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.