{"id":"CVE-2026-64226","summary":"sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Avoid UAF in scx_root_enable_workfn() init failure path\n\nIn scx_root_enable_workfn(), put_task_struct(p) is called before scx_error()\ndereferences p-\u003ecomm and p-\u003epid. If the iterator's reference is the last\ndrop, the task is freed synchronously and the deref becomes a UAF.\n\nMove put_task_struct() past scx_error().","modified":"2026-07-28T04:02:21.553724567Z","published":"2026-07-24T15:23:10.388Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64226.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/45c7c4e3db8b700307313c035ea08be829a7f21b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/57e19ba3f58a67eb924022a5a60b67fd08e5cbbd"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9a415cc53711f2238e0f0ca8a6bcc796c003b127"},{"type":"WEB","url":"https://git.kernel.org/stable/c/cf396941901858b0de426cdcd3974eea6a02c98c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64226.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64226"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f0e1a0643a59bf1f922fa209cec86a170b784f3f"},{"fixed":"cf396941901858b0de426cdcd3974eea6a02c98c"},{"fixed":"45c7c4e3db8b700307313c035ea08be829a7f21b"},{"fixed":"57e19ba3f58a67eb924022a5a60b67fd08e5cbbd"},{"fixed":"9a415cc53711f2238e0f0ca8a6bcc796c003b127"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64226.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.12.0"},{"fixed":"6.12.92"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.34"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.0.11"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64226.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}