CVE-2026-74731

Source
https://cve.org/CVERecord?id=CVE-2026-74731
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74731.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74731
Downstream
Published
2026-08-22T15:33:20Z
Modified
2026-08-27T11:31:11Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
sched_ext: Skip sub-disable teardown for never-linked sub-schedulers
Details

In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Skip sub-disable teardown for never-linked sub-schedulers

A sub-scheduler enable can fail before scx_link_sched() links the sched into the hierarchy, e.g. when the parent is already being disabled, and cleanup still runs the full scx_sub_disable().

That is racy against root disable: drain_descendants() is the only ordering between a sub's disable-time task walk and root disable's all-task teardown, and an unlinked sub is invisible to it. Root's teardown can thus run between the never-linked sub's drain and its walk, exiting every task to no scheduler.

The walk then trips the membership WARN and re-homes the exited tasks onto the dying hierarchy, a use-after-free.

Skip the cgroup ownership reset and the task walk if @sch was never linked, indicated by the empty ->sibling as unlinking only happens later in the same function. The membership WARN remains valid: a linked sub is always waited on by an ancestor's drain.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74731.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
337ec00b1d9c676f637651c2cefddb8612b867ee
Fixed
6428093a4a986c38c9089b5eb32b56d914ef437a
Fixed
8c13364db9c9a43ed286f3a8d0fb9477b1adc43c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74731.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.1.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74731.json"