PT-2026-106548 · Linux · Linux

CVE-2026-98219

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
sched ext: Close the pre-enable ops error claim window
scx alloc and add sched() publishes ops->priv before scx root enable workfn() switches the state to SCX ENABLING. An error claimed via scx bpf error bstr() from an associated BPF program in that window is consumed by scx disable workfn(), which takes the pre-enable shortcut in scx root disable(). The shortcut returns without any teardown and restores SCX DISABLED with an unconditional scx set enable state() xchg racing the enable workfn's own transition. The enable then completes with the claim consumed: the scheduler stays up but can never be disabled again, and bpf scx unreg() frees it while still in use, resulting in a use-after-free. Both WARN ON ONCE()s fire back to back:
WARNING: kernel/sched/ext/ext.c:7522 at scx root enable workfn+0xeec/0x1be0, CPU#3: scx enable help/276
WARNING: kernel/sched/ext/ext.c:6398 at scx root disable+0xb50/0xdb8, CPU#0: sched ext helpe/664
scx root enable workfn() switches to SCX ENABLING before the scheduler allocation, so ops->priv is never visible while SCX DISABLED. The allocation failure path restores SCX DISABLED.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98219

Affected Products

Linux