{"id":"DEBIAN-CVE-2025-68202","details":"In the Linux kernel, the following vulnerability has been resolved:  sched_ext: Fix unsafe locking in the scx_dump_state()  For built with CONFIG_PREEMPT_RT=y kernels, the dump_lock will be converted sleepable spinlock and not disable-irq, so the following scenarios occur:  inconsistent {IN-HARDIRQ-W} -\u003e {HARDIRQ-ON-W} usage. irq_work/0/27 [HC0[0]:SC0[0]:HE1:SE1] takes: (&rq-\u003e__lock){?...}-{2:2}, at: raw_spin_rq_lock_nested+0x2b/0x40 {IN-HARDIRQ-W} state was registered at:    lock_acquire+0x1e1/0x510    _raw_spin_lock_nested+0x42/0x80    raw_spin_rq_lock_nested+0x2b/0x40    sched_tick+0xae/0x7b0    update_process_times+0x14c/0x1b0    tick_periodic+0x62/0x1f0    tick_handle_periodic+0x48/0xf0    timer_interrupt+0x55/0x80    __handle_irq_event_percpu+0x20a/0x5c0    handle_irq_event_percpu+0x18/0xc0    handle_irq_event+0xb5/0x150    handle_level_irq+0x220/0x460    __common_interrupt+0xa2/0x1e0    common_interrupt+0xb0/0xd0    asm_common_interrupt+0x2b/0x40    _raw_spin_unlock_irqrestore+0x45/0x80    __setup_irq+0xc34/0x1a30    request_threaded_irq+0x214/0x2f0    hpet_time_init+0x3e/0x60    x86_late_time_init+0x5b/0xb0    start_kernel+0x308/0x410    x86_64_start_reservations+0x1c/0x30    x86_64_start_kernel+0x96/0xa0    common_startup_64+0x13e/0x148   other info that might help us debug this:  Possible unsafe locking scenario:          CPU0         ----    lock(&rq-\u003e__lock);    \u003cInterrupt\u003e      lock(&rq-\u003e__lock);    *** DEADLOCK ***   stack backtrace:  CPU: 0 UID: 0 PID: 27 Comm: irq_work/0  Call Trace:   \u003cTASK\u003e   dump_stack_lvl+0x8c/0xd0   dump_stack+0x14/0x20   print_usage_bug+0x42e/0x690   mark_lock.part.44+0x867/0xa70   ? __pfx_mark_lock.part.44+0x10/0x10   ? string_nocheck+0x19c/0x310   ? number+0x739/0x9f0   ? __pfx_string_nocheck+0x10/0x10   ? __pfx_check_pointer+0x10/0x10   ? kvm_sched_clock_read+0x15/0x30   ? sched_clock_noinstr+0xd/0x20   ? local_clock_noinstr+0x1c/0xe0   __lock_acquire+0xc4b/0x62b0   ? __pfx_format_decode+0x10/0x10   ? __pfx_string+0x10/0x10   ? __pfx___lock_acquire+0x10/0x10   ? __pfx_vsnprintf+0x10/0x10   lock_acquire+0x1e1/0x510   ? raw_spin_rq_lock_nested+0x2b/0x40   ? __pfx_lock_acquire+0x10/0x10   ? dump_line+0x12e/0x270   ? raw_spin_rq_lock_nested+0x20/0x40   _raw_spin_lock_nested+0x42/0x80   ? raw_spin_rq_lock_nested+0x2b/0x40   raw_spin_rq_lock_nested+0x2b/0x40   scx_dump_state+0x3b3/0x1270   ? finish_task_switch+0x27e/0x840   scx_ops_error_irq_workfn+0x67/0x80   irq_work_single+0x113/0x260   irq_work_run_list.part.3+0x44/0x70   run_irq_workd+0x6b/0x90   ? __pfx_run_irq_workd+0x10/0x10   smpboot_thread_fn+0x529/0x870   ? __pfx_smpboot_thread_fn+0x10/0x10   kthread+0x305/0x3f0   ? __pfx_kthread+0x10/0x10   ret_from_fork+0x40/0x70   ? __pfx_kthread+0x10/0x10   ret_from_fork_asm+0x1a/0x30   \u003c/TASK\u003e  This commit therefore use rq_lock_irqsave/irqrestore() to replace rq_lock/unlock() in the scx_dump_state().","modified":"2026-08-27T22:48:38.315714829Z","published":"2025-12-16T14:15:53.047Z","upstream":["CVE-2025-68202"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-68202"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.63-1"}]}],"versions":["6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1~bpo12+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68202.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.17.9-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.10-1","6.16.11-1","6.16.12-1","6.16.12-1~bpo13+1","6.16.12-2","6.16.3-1","6.16.3-1~bpo13+1","6.16.5-1","6.16.6-1","6.16.7-1","6.16.8-1","6.16.9-1","6.16~rc7-1~exp1","6.17.2-1~exp1","6.17.5-1~exp1","6.17.6-1","6.17.7-1","6.17.7-2","6.17.8-1","6.17.8-1~bpo13+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68202.json"}}],"schema_version":"1.9.0"}