Junglewise Threat Intelligence

CVE-2026-74731: Linux kernel sched_ext use-after-free in sub-scheduler teardown

CVE-2026-74731 · Severity: high · CVSS 7.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's extensible scheduler (sched_ext) contains a race condition during sub-scheduler cleanup that can lead to a use-after-free vulnerability. When a sub-scheduler initialization fails before being linked into the scheduler hierarchy, the cleanup code attempts to walk and re-home tasks that have already been exited by the root scheduler, causing memory corruption. An attacker with appropriate permissions to enable/disable schedulers could trigger this condition, potentially leading to kernel crash or privilege escalation.

Technical details

The vulnerability is a use-after-free race condition in the scx_sub_disable() function within the Linux kernel's sched_ext subsystem. The root cause is improper synchronization during sub-scheduler disable teardown: when a sub-scheduler enable fails before scx_link_sched() links it into the hierarchy, the cleanup still executes the full scx_sub_disable() sequence. However, an unlinked scheduler is invisible to drain_descendants(), the primary ordering mechanism. Root's all-task teardown can thus run between the never-linked sub's task drain and its task walk, exiting every task to no scheduler. The subsequent walk then attempts to reparent already-exited tasks onto the dying hierarchy, triggering a WARN and use-after-free. The fix skips the cgroup ownership reset and task walk for schedulers that were never linked (detected by empty sibling list), while keeping the membership WARN intact for properly-linked schedulers.

Affected products

  • Linux Linux kernel 5.12+

Timeline

  • 2026-08-22: disclosed
  • 2026-07-16: patched: Fix committed upstream by Tejun Heo

References

Related threats