{"id":"CVE-2026-64226","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Avoid UAF in scx_root_enable_workfn() init failure path\n\nIn scx_root_enable_workfn(), put_task_struct(p) is called before scx_error()\ndereferences p->comm an…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Avoid UAF in scx_root_enable_workfn() init failure path\n\nIn scx_root_enable_workfn(), put_task_struct(p) is called before scx_error()\ndereferences p->comm an…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","published":"2026-07-24","updated":"2026-07-27","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-64226","references":[{"url":"https://git.kernel.org/stable/c/45c7c4e3db8b700307313c035ea08be829a7f21b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/57e19ba3f58a67eb924022a5a60b67fd08e5cbbd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9a415cc53711f2238e0f0ca8a6bcc796c003b127","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cf396941901858b0de426cdcd3974eea6a02c98c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00129,"epssPercentile":0.02923,"ingestedAt":"2026-07-27T06:16:49.264Z","slug":"CVE-2026-64226","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Avoid UAF in scx_root_enable_workfn() init failure path\n\nIn scx_root_enable_workfn(), put_task_struct(p) is called before scx_error()\ndereferences p->comm and p->pid. If the iterator's reference is the last\ndrop, the task is freed synchronously and the deref becomes a UAF.\n\nMove put_task_struct() past scx_error().\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}