Executive brief
A vulnerability was identified in the Linux kernel's scheduling extensible (sched_ext) component, which manages how the operating system allocates processing power to different tasks. A flaw in how the system tracks internal resource references could allow a local attacker to cause a system crash or potentially execute unauthorized code. This issue primarily affects systems utilizing cgroups for resource management and isolation.
Technical details
A use-after-free (UAF) vulnerability exists in the Linux kernel within the sched_ext (Extensible Scheduler) framework. The root cause is a reference count underflow in the scx_cgroup_init() function. The iterator css_for_each_descendant_pre() walks the cgroup hierarchy without incrementing reference counts on the yielded css structs. However, the error path in scx_cgroup_init() incorrectly called css_put(), leading to an unbalanced reference count. A local attacker could exploit this underflow to trigger a use-after-free condition, potentially leading to local privilege escalation or a kernel panic. The issue has been resolved by removing the redundant css_put() call in the error path.
Affected products
- Linux Linux Kernel 6.12 to 6.12.78, 6.13 to 6.18.19, 6.19 to 6.19.9, 7.0-rc1, 7.0-rc2
Timeline
- 2026-05-08: advisory: Initial disclosure of CVE-2026-43438
- 2026-03-03: patched: Fix committed to the Linux kernel tree