SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64226

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

A use-after-free vulnerability exists in the Linux kernel's `scx_root_enable_workfn()` function, where a task structure is freed before its properties are accessed, potentially leading to arbitrary code execution or system crashes. This high-severity flaw primarily affects Linux-based systems, and organizations running affected kernel versions should prioritize patching to mitigate the risk of exploitation. System administrators and security teams should assess their environments for vulnerable kernel versions and apply the necessary updates promptly.

CVE
CVE-2026-64226
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path In scx_root_enable_workfn(), put_task_struct(p) is called before scx_error() dereferences p->comm and p->pid. If the iterator's reference is the last drop, the task is freed synchronously and the deref becomes a UAF. Move put_task_struct() past scx_error().

Related CVEs

Other vulnerabilities affecting the same vendor(s)