Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: sched_ext: Read scx_root under scx_cgroup_ops_rwsem in cgroup setters… (CVE-2026-46154)
A use-after-free vulnerability in the Linux kernel's scheduler extension (sched_ext) was resolved. The flaw involves reading a stale pointer (scx_root) under the scx_cgroup_ops_rwsem lock in cgroup setter functions, potentially leading to dereferencing freed memory. This can occur if the scheduler is disabled and freed while another is enabled concurrently. The vulnerability affects multiple Linux kernel versions prior to 7.0.0-28.28 and related builds. The issue has been assigned CVE-2026-46154 and carries a CVSS 3.1 score of 7.0, indicating a medium severity. A patch is available and included in updated Linux kernel packages for Ubuntu 26.04 LTS and related variants. Users should apply the updates and reboot to mitigate the risk.
AI Analysis
Technical Summary
CVE-2026-46154 is a use-after-free vulnerability in the Linux kernel's scheduler extension (sched_ext). The vulnerability arises because the pointer scx_root is read outside the protection of the scx_cgroup_ops_rwsem lock in cgroup setter functions such as scx_group_set_weight, idle, and bandwidth. If the scheduler is disabled and freed via RCU work while another scheduler is enabled between the pointer load and lock acquisition, the code may dereference a freed scheduler structure, causing a use-after-free condition. This flaw can lead to high impact on confidentiality, integrity, and availability as indicated by the CVSS vector. The vulnerability affects multiple Linux kernel versions prior to 7.0.0-28.28 and related builds. Ubuntu has released patches in kernel versions 7.0.0-28.28 and later for various kernel flavors including generic, GCP, GKE, OEM, and realtime kernels. Users must update and reboot to apply the fix.
Potential Impact
Successful exploitation of this use-after-free vulnerability could allow a local attacker with low privileges to cause a kernel crash or potentially escalate privileges by corrupting kernel memory. The CVSS score of 7.0 reflects a medium severity with high impact on confidentiality, integrity, and availability. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
A patch is available and has been released by Ubuntu in kernel versions 7.0.0-28.28 and later for various kernel flavors. Users should update their Linux kernel packages to the fixed versions listed in the Ubuntu advisories USN-8566-1 and USN-8568-1 and reboot their systems to apply the fixes. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be required. No additional mitigation steps are indicated by the vendor.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: sched_ext: Read scx_root under scx_cgroup_ops_rwsem in cgroup setters… (CVE-2026-46154)
Description
A use-after-free vulnerability in the Linux kernel's scheduler extension (sched_ext) was resolved. The flaw involves reading a stale pointer (scx_root) under the scx_cgroup_ops_rwsem lock in cgroup setter functions, potentially leading to dereferencing freed memory. This can occur if the scheduler is disabled and freed while another is enabled concurrently. The vulnerability affects multiple Linux kernel versions prior to 7.0.0-28.28 and related builds. The issue has been assigned CVE-2026-46154 and carries a CVSS 3.1 score of 7.0, indicating a medium severity. A patch is available and included in updated Linux kernel packages for Ubuntu 26.04 LTS and related variants. Users should apply the updates and reboot to mitigate the risk.
CVSS v3.1
Score 7.0high
Affected software
pkg:deb/ubuntu/[email protected]~16.04.1?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.2?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.2?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~18.04.1?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.2?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]+cvm1.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.3?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~20.04.1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.2?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.2.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=bluefield/noblepkg:deb/ubuntu/[email protected]~24.04.1?arch=source&distro=realtime/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-46154 is a use-after-free vulnerability in the Linux kernel's scheduler extension (sched_ext). The vulnerability arises because the pointer scx_root is read outside the protection of the scx_cgroup_ops_rwsem lock in cgroup setter functions such as scx_group_set_weight, idle, and bandwidth. If the scheduler is disabled and freed via RCU work while another scheduler is enabled between the pointer load and lock acquisition, the code may dereference a freed scheduler structure, causing a use-after-free condition. This flaw can lead to high impact on confidentiality, integrity, and availability as indicated by the CVSS vector. The vulnerability affects multiple Linux kernel versions prior to 7.0.0-28.28 and related builds. Ubuntu has released patches in kernel versions 7.0.0-28.28 and later for various kernel flavors including generic, GCP, GKE, OEM, and realtime kernels. Users must update and reboot to apply the fix.
Potential Impact
Successful exploitation of this use-after-free vulnerability could allow a local attacker with low privileges to cause a kernel crash or potentially escalate privileges by corrupting kernel memory. The CVSS score of 7.0 reflects a medium severity with high impact on confidentiality, integrity, and availability. No known exploits in the wild have been reported at this time.
Mitigation Recommendations
A patch is available and has been released by Ubuntu in kernel versions 7.0.0-28.28 and later for various kernel flavors. Users should update their Linux kernel packages to the fixed versions listed in the Ubuntu advisories USN-8566-1 and USN-8568-1 and reboot their systems to apply the fixes. Due to an ABI change, recompilation and reinstallation of third-party kernel modules may be required. No additional mitigation steps are indicated by the vendor.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-46154
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:Nvidia-BlueField:24.04:LTS","Ubuntu:Pro:Realtime:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a5a01eb91ae9bcd3f82fc46
Added to database: 07/17/2026, 10:20:27 UTC
Last enriched: 09/08/2026, 00:37:55 UTC
Last updated: 09/11/2026, 07:31:53 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.