CVE-2026-43438

Description

A flaw was found in the Linux kernel's sched_ext component. This vulnerability is caused by a redundant css_put() call in the scx_cgroup_init() function, leading to a reference count underflow. This can result in a Use-After-Free (UAF) vulnerability, potentially allowing a local attacker to cause a denial of service or achieve privilege escalation.

Understanding the Weakness (CWE)

Availability,Integrity

Technical Impact: DoS: Crash, Exit, or Restart

Frequently Asked Questions

Want to get errata notifications? Sign up here.