PT-2026-94978 · Linux · Linux Kernel
CVE-2026-93182
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel version 7.1.0-rc2
Description
A divide-by-zero crash occurs due to a
u32 overflow in the update tg cfs runnable() function. This overflow corrupts the runnable sum, which subsequently leads to an incorrect runnable avg calculation. The corruption propagates through update tg load avg(), calc concur shares(), and reweight entity(), eventually resulting in a corrupted cfs rq->load.weight. When the div u64() function is called within propagate entity load avg(), the large value of gcfs rq->load.weight is truncated to its lower 32 bits, which can be zero, triggering the crash.Recommendations
Update the Linux kernel to a version where the
new sum variable in the update tg cfs runnable() function is widened from u32 to u64.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel