{"id":"CVE-2026-98220","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Fix NULL sched deref in kfunc sub-sched error paths\n\nWhen the root scheduler has sub-scheds attached, the COMPAT kfunc\nwrappers scx_bpf_select_cpu_and() and …","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Fix NULL sched deref in kfunc sub-sched error paths\n\nWhen the root scheduler has sub-scheds attached, the COMPAT kfunc\nwrappers scx_bpf_select_cpu_and() and …","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= a5fa0708cbfda4d3c2c6a447de7c4b0b23595527 < 589f0945bf3ebf0790fd51e28c7f0d04ed3d8b78","Linux >= a5fa0708cbfda4d3c2c6a447de7c4b0b23595527 < 0a85182723b65ad8bee8131bc38fcf0347d6679b","Linux 7.1"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:08.857","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98220","references":[{"url":"https://git.kernel.org/stable/c/0a85182723b65ad8bee8131bc38fcf0347d6679b","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/589f0945bf3ebf0790fd51e28c7f0d04ed3d8b78","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.439Z","slug":"CVE-2026-98220","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Fix NULL sched deref in kfunc sub-sched error paths\n\nWhen the root scheduler has sub-scheds attached, the COMPAT kfunc\nwrappers scx_bpf_select_cpu_and() and scx_bpf_dsq_insert_vtime() refuse\nthe call and report to @p's scheduler:\n\n\tscx_error(scx_task_sched(p), \"... must be used\");\n\nThe wrappers are reachable with tasks that have no scheduler.\nscx_bpf_select_cpu_and() is in the select_cpu kfunc group, which\nscx_kfunc_context_filter() opens to BPF_PROG_TYPE_SYSCALL programs;\nscx_bpf_dsq_insert_vtime() is in the enqueue_dispatch group, which\nops.enqueue() and ops.dispatch() may call with any KF_RCU task -- the\ngroup has no kf_tasks validation, and scx_dsq_insert_preamble() checks\ntask ownership with scx_task_on_sched() precisely because @p may be an\narbitrary task.\n\nscx_task_sched(p) is p->scx.sched, which is NULL for tasks past\nsched_ext_dead() -- which clears it via scx_disable_and_exit_task() on\nexit -- and for idle tasks, which the enable paths skip as they are\nnever scheduled through SCX. It is also an rcu_dereference_protected()\nthat expects @p's pi_lock or rq lock, which neither wrapper holds.\nPassing NULL to scx_error() reaches scx_vexit(), which dereferences\nsch->exit_info, oopsing the kernel.\n\nOne concrete trigger exercised while developing the fix: a\nBPF_PROG_TYPE_SYSCALL program calling the select_cpu_and wrapper on an\nexited-but-not-reaped task while a sub-scheduler was attached (its pid\nstays findable while the zombie is unreaped; faulting instruction is\nthe scx_vexit() prologue \"mov r15,[rdi+0x398]\" with RDI=NULL and 0x398\nthe offset of sch->exit_info):\n\n  sched_ext: BPF scheduler \"kfunc_subsched_null\" enabled\n  sched_ext: BPF sub-scheduler \"kfunc_subsched_null\" enabled\n  sched_ext: Unassociated program run_select_cpu_ (id 76)\n  BUG: kernel NULL pointer dereference, address: 0000000000000398\n  #PF: supervisor read access in kernel mode\n  #PF: error_code(0x0000) - not-present page\n  Oops: Oops: 0000 [#1] SMP NOPTI\n  CPU: 7 UID: 0 PID: 8201 Comm: kfunc_test_runn Tainted: G W\n  RIP: 0010:scx_vexit+0x25/0xa0\n  Code: ... <4c> 8b bf 98 03 00 00 ...\n  CR2: 0000000000000398\n  Call Trace:\n   <TASK>\n   __scx_exit+0x4f/0x70\n   scx_bpf_select_cpu_and+0xab/0xb0\n   bpf_prog_430ed61a7b66e03a_run_select_cpu_and+0x9c/0xe7\n   ? __x64_sys_bpf+0x2c/0x40\n   bpf_prog_test_run_syscall+0x130/0x2f0\n   __sys_bpf+0x930/0x10d0\n   ? __x64_sys_bpf+0x2c/0x40\n   __x64_sys_bpf+0x2c/0x40\n   do_syscall_64+0xbc/0x460\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e\n   </TASK>\n\nRead @p's scheduler under RCU instead, which the wrappers can do from\ntheir guard(rcu)(): fault it when it can be determined, and when it\ncan't be determined -- @p is a task past sched_ext_dead() or an idle\ntask -- there is nothing obviously wrong to report, so just refuse the\ncall as before without faulting any scheduler.\n\nThese COMPAT wrappers are scheduled for eventual removal once the\ndeprecation grace period elapses, but until then -- and regardless of\ntheir removal timeline -- they must not oops the kernel on a task they\nare handed.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}