Back

MEDIUM

sched_ext: Fix starvation of scx_enable() under fair-class saturation

Published May 8, 2026

Description

During scx_enable(), the READY -> ENABLED task switching loop changes the calling thread's sched_class from fair to ext. Since fair has higher priority than ext, saturating fair-class workloads can indefinitely starve the enable thread, hanging the system. This was introduced when the enable path switched from preempt_disable() to scx_bypass() which doesn't protect against fair-class starvation. Note that the original preempt_disable() protection wasn't complete either - in partial switch modes, the calling thread could still be starved after preempt_enable() as it may have been switched to ext class.

Fix it by offloading the enable body to a dedicated system-wide RT (SCHED_FIFO) kthread which cannot be starved by either fair or ext class tasks. scx_enable() lazily creates the kthread on first use and passes the ops pointer through a struct scx_enable_cmd containing the kthread_work, then synchronously waits for completion.

The workfn runs on a different kthread from sch->helper (which runs disable_work), so it can safely flush disable_work on the error path without deadlock.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published May 8, 2026
Updated May 11, 2026
Reserved May 1, 2026

CISA Vulnrichment

No data

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

Public date May 8, 2026
Bugzilla 2468221

ENISA EUVD

Assigner Linux
Published May 8, 2026
Updated May 11, 2026

GitHub

No data