CVE-2026-64226

Source
https://cve.org/CVERecord?id=CVE-2026-64226
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64226.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64226
Downstream
Published
2026-07-24T15:23:10.388Z
Modified
2026-07-28T04:02:21.553724567Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
Details

In the Linux kernel, the following vulnerability has been resolved:

schedext: Avoid UAF in scxrootenableworkfn() init failure path

In scxrootenableworkfn(), puttaskstruct(p) is called before scxerror() dereferences p->comm and p->pid. If the iterator's reference is the last drop, the task is freed synchronously and the deref becomes a UAF.

Move puttaskstruct() past scx_error().

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64226.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f0e1a0643a59bf1f922fa209cec86a170b784f3f
Fixed
cf396941901858b0de426cdcd3974eea6a02c98c
Fixed
45c7c4e3db8b700307313c035ea08be829a7f21b
Fixed
57e19ba3f58a67eb924022a5a60b67fd08e5cbbd
Fixed
9a415cc53711f2238e0f0ca8a6bcc796c003b127

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64226.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.92
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64226.json"