Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-64226— sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path

CVSS 7.8 · High EPSS 0.13% · P3

Affected Version Matrix 10

VendorProductVersion RangeStatus
LinuxLinuxf0e1a0643a59bf1f922fa209cec86a170b784f3f< cf396941901858b0de426cdcd3974eea6a02c98caffected
f0e1a0643a59bf1f922fa209cec86a170b784f3f< 45c7c4e3db8b700307313c035ea08be829a7f21baffected
f0e1a0643a59bf1f922fa209cec86a170b784f3f< 57e19ba3f58a67eb924022a5a60b67fd08e5cbbdaffected
f0e1a0643a59bf1f922fa209cec86a170b784f3f< 9a415cc53711f2238e0f0ca8a6bcc796c003b127affected
6.12affected
< 6.12unaffected
6.12.92≤ 6.12.*unaffected
6.18.34≤ 6.18.*unaffected
… +2 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-64226

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path In scx_root_enable_workfn(), put_task_struct(p) is called before scx_error() dereferences p->comm and p->pid. If the iterator's reference is the last drop, the task is freed synchronously and the deref becomes a UAF. Move put_task_struct() past scx_error().
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 6.12版本存在安全漏洞,该漏洞源于scx_root_enable_workfn()函数中put_task_struct(p)在scx_error()解引用p->comm和p->pid之前调用,导致释放后重用(UAF)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux f0e1a0643a59bf1f922fa209cec86a170b784f3f ~ cf396941901858b0de426cdcd3974eea6a02c98c -
LinuxLinux 6.12 -

II. Public POCs for CVE-2026-64226

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-64226

登录查看更多情报信息。

Patches & Fixes for CVE-2026-64226 (4)

Same Patch Batch · Linux · 2026-07-24 · 48 CVEs total

CVE-2026-642329.8 CRITICALblock: recompute nr_integrity_segments in blk_insert_cloned_request
CVE-2026-642169.8 CRITICALnetfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()
CVE-2026-642558.8 HIGHwifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
CVE-2026-642478.4 HIGHKVM: x86: hyper-v: Bound the bank index when querying sparse banks
CVE-2026-642358.1 HIGHx86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines
CVE-2026-642238.1 HIGHwifi: mac80211: consume only present negotiated TTLM maps
CVE-2026-642517.8 HIGHpwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()
CVE-2026-642217.8 HIGHspi: ti-qspi: fix use-after-free after DMA setup failure
CVE-2026-642187.8 HIGHbatman-adv: bla: fix report_work leak on backbone_gw purge
CVE-2026-642177.8 HIGHnetfs: Fix overrun check in netfs_extract_user_iter()
CVE-2026-642107.5 HIGHnet/mlx5e: xsk: Fix unlocked writing to ICOSQ
CVE-2026-642087.5 HIGHcrypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks
CVE-2026-642437.1 HIGHASoC: codecs: simple-mux: Fix enum control bounds check
CVE-2026-642227.0 HIGHocteontx2-pf: avoid double free of pool->stack on AQ init failure
CVE-2026-642197.0 HIGHdrm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_as
CVE-2026-64252MIPS: DEC: Prevent initial console buffer from landing in XKPHYS
CVE-2026-64246power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
CVE-2026-64250LoongArch: Report dying CPU to RCU in stop_this_cpu()
CVE-2026-64248MIPS: smp: report dying CPU to RCU in stop_this_cpu()
CVE-2026-64254NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR

Showing top 20 of 48 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-64226

No comments yet


Leave a comment