{"id":"AZL-101855","summary":"CVE-2026-93150 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: Make nr_deadline_tasks an atomic_t\n\nThe nr_deadline_tasks variable in the cpuset structure was introduced by\ncommit 6c24849f5515 (\"sched/cpuset: Keep track of SCHED_DEADLINE task\nin cpusets\"). It is reported by sashiko [1] that nr_deadline_tasks\ncan currently be modified by inc_dl_tasks_cs() under rq-\u003elock and\nby cpuset_attach() under cpuset_mutex. So if both updates happen\nsimultaneously, the nr_deadline_tasks variable can be corrupted leading\nto incorrect operations down the road.\n\nFix that by changing its type to atomic_t so that nr_deadline_tasks\nare always atomically updated. This fix patch is a low hanging fruit.\nIt can handle some of the races between a concurrent sched_setscheduler()\nand cpuset_can_attach()/cpuset_attach() calls, but not all of them like\nthe other issue raised by sashiko [2]. This will be handled hopefully\nin a future follow up patch.\n\n[1] https://sashiko.dev/#/patchset/20260626181923.133658-1-longman%40redhat.com\n[2] https://sashiko.dev/#/patchset/20260630033344.352702-1-longman%40redhat.com","modified":"2026-09-18T14:16:29.137742776Z","published":"2026-09-17T17:18:10Z","upstream":["CVE-2026-93150"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93150"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-101855.json"}}],"schema_version":"1.9.0"}