PT-2026-106548 · Linux · Linux
CVE-2026-98219
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
sched ext: Close the pre-enable ops error claim window
scx alloc and add sched() publishes ops->priv before
scx root enable workfn() switches the state to SCX ENABLING. An error
claimed via scx bpf error bstr() from an associated BPF program in that
window is consumed by scx disable workfn(), which takes the pre-enable
shortcut in scx root disable(). The shortcut returns without any teardown
and restores SCX DISABLED with an unconditional scx set enable state() xchg
racing the enable workfn's own transition. The enable then completes with
the claim consumed: the scheduler stays up but can never be disabled again,
and bpf scx unreg() frees it while still in use, resulting in a
use-after-free. Both WARN ON ONCE()s fire back to back:
WARNING: kernel/sched/ext/ext.c:7522 at
scx root enable workfn+0xeec/0x1be0, CPU#3: scx enable help/276
WARNING: kernel/sched/ext/ext.c:6398 at scx root disable+0xb50/0xdb8,
CPU#0: sched ext helpe/664
scx root enable workfn() switches to SCX ENABLING before the scheduler
allocation, so ops->priv is never visible while SCX DISABLED. The allocation
failure path restores SCX DISABLED.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux