VYPR
Medium severity5.5NVD Advisory· Published Jan 21, 2025· Updated Jun 17, 2026

CVE-2025-21657

CVE-2025-21657

Description

In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Replace rq_lock() to raw_spin_rq_lock() in scx_ops_bypass()

scx_ops_bypass() iterates all CPUs to re-enqueue all the scx tasks. For each CPU, it acquires a lock using rq_lock() regardless of whether a CPU is offline or the CPU is currently running a task in a higher scheduler class (e.g., deadline). The rq_lock() is supposed to be used for online CPUs, and the use of rq_lock() may trigger an unnecessary warning in rq_pin_lock(). Therefore, replace rq_lock() to raw_spin_rq_lock() in scx_ops_bypass().

Without this change, we observe the following warning:

===== START ===== [ 6.615205] rq->balance_callback && rq->balance_callback != &balance_push_callback [ 6.615208] WARNING: CPU: 2 PID: 0 at kernel/sched/sched.h:1730 __schedule+0x1130/0x1c90 ===== END =====

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

13
  • Linux/Kernelcpe-rescue12 versions
    6.12+ 11 more
    • (no CPE)range: 6.12
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.12.1,<6.12.10
    • cpe:2.3:o:linux:linux_kernel:6.12:-:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.12:rc6:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.12:rc7:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.13:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.13:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.13:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.13:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:6.13:rc6:*:*:*:*:*:*
    • (no CPE)
  • osv-coords
    Range: >= 6.12.0, < 6.12.10

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.