Database/Kernel, userspace & hypervisor
Linux kernel sched_ext: a failed sub-scheduler enable races root disable into a use-after-free
Impact
A sub-scheduler enable can fail before scx_link_sched() puts it in the hierarchy, yet cleanup still runs the full scx_sub_disable() path. An unlinked sub is invisible to drain_descendants(), which is the only ordering against root disable, so root teardown can exit every task to no scheduler between the sub's drain and its task walk; the walk then trips the membership WARN and re-homes exited tasks onto the dying hierarchy - a use-after-free. This only affects fleets that run BPF schedulers, which some operators do adopt on GPU nodes to tune data-loader and rank latency; on those, the failure mode is a kernel-side crash of the node's scheduling.
Who can reach it
Local root or CAP_SYS_ADMIN able to attach sched_ext schedulers, and specifically to a hierarchy with sub-schedulers where an enable fails while the root is being disabled. Not reachable by tenant workloads. Nodes with no scx scheduler loaded have no exposure.
What to do
Update to a stable kernel with the fix and reboot the node. Until then, the cheap interim is to avoid nested sub-scheduler hierarchies and to not tear down the root scheduler while sub-scheduler enables are in flight; unloading scx entirely removes the path if the latency tuning can wait.
References
Related entries
- Linux kernel perf/core: exited event accepted as group leader leaves a sibling pointing at freed memoryCVE-2026-74753 · Linux kernel perf/core (perf_event_open group-leader state validation)Unscored
- Xen: guest with a passthrough PCI device exposing an IO port BAR can trigger a hypervisor BUG()CVE-2026-79602 · Xen hypervisor (PCI passthrough, IO port BAR handling)Unscored
- libcurl: pooled TLS connection outlives its easy handle and reuses a freed OpenSSL library contextCVE-2026-80229 · libcurl (multi interface, OpenSSL 3 provider library context)Unscored
- Linux kernel CephFS client: readers hang indefinitely after cap revocation leaves stale mds_wantedCVE-2026-80527 · Linux kernel CephFS client (__ceph_get_caps / ceph_renew_caps, stale cap->mds_wanted)Unscored
- Linux kernel CephFS client: reclaim during MDS reply handling crashes the kernel via ext4 journal_infoCVE-2026-80528 · Linux kernel CephFS client (handle_reply / current->journal_info vs direct reclaim)Unscored
- Linux kernel libceph: out-of-bounds read in decode_watchers() from a zero-length struct_lenCVE-2026-80557 · Linux kernel libceph (decode_watchers(), CEPH_OSD_OP_LIST_WATCHERS reply parsing)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.