Vulnerabilities & PatchesEmerging1 src
CVE-2026-74731 - sched_ext: Skip sub-disable teardown for never-linked sub-schedulers
CVE ID : CVE-2026-74731
Published : Aug. 22, 2026, 4:16 p. m.
• 4 hours, 54 minutes ago
Description : In the Linux kernel, the following vulnerability has been resolved:
sched_ext: Skip sub-disable teardown for never-linked sub-schedulers
A sub-scheduler enable can fail before scx_link_sched() links the sched into the hierarchy, e. g. when the parent is already being disabled, and cleanup still runs the full scx_sub_disable().
That is racy against root disable: drain_descendants() is the only ordering between a sub's disable-time task walk and root disable's all-task teardown, and an unlinked sub is invisible to it. Root's teardown can thus run between the never-linked sub's drain and its walk, exiting every task to no scheduler.
The walk then trips the membership WARN and re-homes the exited tasks onto the dying hierarchy, a use-after-free.