CVE-2026-43438
Description
A flaw was found in the Linux kernel's sched_ext component. This vulnerability is caused by a redundant css_put() call in the scx_cgroup_init() function, leading to a reference count underflow. This can result in a Use-After-Free (UAF) vulnerability, potentially allowing a local attacker to cause a denial of service or achieve privilege escalation.
Understanding the Weakness (CWE)
Availability,Integrity
Technical Impact: DoS: Crash, Exit, or Restart
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.