Junglewise Threat Intelligence

CVE-2026-43438: Linux Kernel use-after-free in sched_ext scx_cgroup_init

CVE-2026-43438 · Severity: high · CVSS 7.8 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's scheduling extensible (sched_ext) component, which manages how the operating system allocates processing power to different tasks. A flaw in how the system tracks internal resource references could allow a local attacker to cause a system crash or potentially execute unauthorized code. This issue primarily affects systems utilizing cgroups for resource management and isolation.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel within the sched_ext (Extensible Scheduler) framework. The root cause is a reference count underflow in the scx_cgroup_init() function. The iterator css_for_each_descendant_pre() walks the cgroup hierarchy without incrementing reference counts on the yielded css structs. However, the error path in scx_cgroup_init() incorrectly called css_put(), leading to an unbalanced reference count. A local attacker could exploit this underflow to trigger a use-after-free condition, potentially leading to local privilege escalation or a kernel panic. The issue has been resolved by removing the redundant css_put() call in the error path.

Affected products

  • Linux Linux Kernel 6.12 to 6.12.78, 6.13 to 6.18.19, 6.19 to 6.19.9, 7.0-rc1, 7.0-rc2

Timeline

  • 2026-05-08: advisory: Initial disclosure of CVE-2026-43438
  • 2026-03-03: patched: Fix committed to the Linux kernel tree

References

Related threats