SB20260824246 - Use-after-free in Linux kernel sched
Published: August 24, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-74594)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in kernel/sched/psi.c when destroying PSI cgroup triggers concurrently with scheduling poll work. A local user can trigger a race that leaves a poll timer pending on freed memory to cause a denial of service.
The issue occurs because a timer may be re-armed during teardown and later execute poll_timer_fn() after the associated group has been freed.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1e5ca82eee59caca6988f9d6e859786aab8a5fa0
- https://git.kernel.org/stable/c/310b5a537a78c358a4cd244bd767c1a517a05459
- https://git.kernel.org/stable/c/4addb102154b7cf6e2310ccbe20c3c08619e520d
- https://git.kernel.org/stable/c/5457025fa8ca3c0d2732109513de839e3e797190
- https://git.kernel.org/stable/c/611e7821c4f83a671455658797336faecc3a5196
- https://git.kernel.org/stable/c/8037c5b2b2a447df52542f4d8535895d837bdcbd
- https://git.kernel.org/stable/c/806fcff98c1d7cb3c1dc0015e55ebdbe819e6b08
- https://git.kernel.org/stable/c/894a9300d7fb2e2951da92e565ae6de7ddfb0a69