« Volver al listado

CVE-2026-98220

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

sched_ext: Fix NULL sched deref in kfunc sub-sched error paths

When the root scheduler has sub-scheds attached, the COMPAT kfunc wrappers scx_bpf_select_cpu_and() and scx_bpf_dsq_insert_vtime() refuse the call and report to @p's scheduler:

The wrappers are reachable with tasks that have no scheduler. scx_bpf_select_cpu_and() is in the select_cpu kfunc group, which scx_kfunc_context_filter() opens to BPF_PROG_TYPE_SYSCALL programs; scx_bpf_dsq_insert_vtime() is in the enqueue_dispatch group, which ops.enqueue() and ops.dispatch() may call with any KF_RCU task -- the group has no kf_tasks validation, and scx_dsq_insert_preamble() checks task ownership with scx_task_on_sched() precisely because @p may be an arbitrary task.

Leer descripción completaMostrar menos

scx_task_sched(p) is p->scx.sched, which is NULL for tasks past sched_ext_dead() -- which clears it via scx_disable_and_exit_task() on exit -- and for idle tasks, which the enable paths skip as they are never scheduled through SCX. It is also an rcu_dereference_protected() that expects @p's pi_lock or rq lock, which neither wrapper holds. Passing NULL to scx_error() reaches scx_vexit(), which dereferences sch->exit_info, oopsing the kernel.

One concrete trigger exercised while developing the fix: a BPF_PROG_TYPE_SYSCALL program calling the select_cpu_and wrapper on an exited-but-not-reaped task while a sub-scheduler was attached (its pid stays findable while the zombie is unreaped; faulting instruction is the scx_vexit() prologue "mov r15,[rdi+0x398]" with RDI=NULL and 0x398 the offset of sch->exit_info):

Read @p's scheduler under RCU instead, which the wrappers can do from their guard(rcu)(): fault it when it can be determined, and when it can't be determined -- @p is a task past sched_ext_dead() or an idle task -- there is nothing obviously wrong to report, so just refuse the call as before without faulting any scheduler.

These COMPAT wrappers are scheduled for eventual removal once the deprecation grace period elapses, but until then -- and regardless of their removal timeline -- they must not oops the kernel on a task they are handed.

Detalles técnicos trazas, registros y código del informe original
	scx_error(scx_task_sched(p), "... must be used");

  sched_ext: BPF scheduler "kfunc_subsched_null" enabled
  sched_ext: BPF sub-scheduler "kfunc_subsched_null" enabled
  sched_ext: Unassociated program run_select_cpu_ (id 76)
  BUG: kernel NULL pointer dereference, address: 0000000000000398
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not-present page
  Oops: Oops: 0000 [#1] SMP NOPTI
  CPU: 7 UID: 0 PID: 8201 Comm: kfunc_test_runn Tainted: G W
  RIP: 0010:scx_vexit+0x25/0xa0
  Code: ... <4c> 8b bf 98 03 00 00 ...
  CR2: 0000000000000398
  Call Trace:
   <TASK>
   __scx_exit+0x4f/0x70
   scx_bpf_select_cpu_and+0xab/0xb0
   bpf_prog_430ed61a7b66e03a_run_select_cpu_and+0x9c/0xe7
   ? __x64_sys_bpf+0x2c/0x40
   bpf_prog_test_run_syscall+0x130/0x2f0
   __sys_bpf+0x930/0x10d0
   ? __x64_sys_bpf+0x2c/0x40
   __x64_sys_bpf+0x2c/0x40
   do_syscall_64+0xbc/0x460
   entry_SYSCALL_64_after_hwframe+0x76/0x7e
   </TASK>

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98220",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "a5fa0708cbfda4d3c2c6a447de7c4b0b23595527",
              "lessThan": "589f0945bf3ebf0790fd51e28c7f0d04ed3d8b78",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a5fa0708cbfda4d3c2c6a447de7c4b0b23595527",
              "lessThan": "0a85182723b65ad8bee8131bc38fcf0347d6679b",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "kernel/sched/ext/ext.c",
            "kernel/sched/ext/idle.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "kernel/sched/ext/ext.c",
            "kernel/sched/ext/idle.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:08.857",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0a85182723b65ad8bee8131bc38fcf0347d6679b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/589f0945bf3ebf0790fd51e28c7f0d04ed3d8b78",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Fix NULL sched deref in kfunc sub-sched error paths\n\nWhen the root scheduler has sub-scheds attached, the COMPAT kfunc\nwrappers scx_bpf_select_cpu_and() and scx_bpf_dsq_insert_vtime() refuse\nthe call and report to @p's scheduler:\n\n\tscx_error(scx_task_sched(p), \"... must be used\");\n\nThe wrappers are reachable with tasks that have no scheduler.\nscx_bpf_select_cpu_and() is in the select_cpu kfunc group, which\nscx_kfunc_context_filter() opens to BPF_PROG_TYPE_SYSCALL programs;\nscx_bpf_dsq_insert_vtime() is in the enqueue_dispatch group, which\nops.enqueue() and ops.dispatch() may call with any KF_RCU task -- the\ngroup has no kf_tasks validation, and scx_dsq_insert_preamble() checks\ntask ownership with scx_task_on_sched() precisely because @p may be an\narbitrary task.\n\nscx_task_sched(p) is p->scx.sched, which is NULL for tasks past\nsched_ext_dead() -- which clears it via scx_disable_and_exit_task() on\nexit -- and for idle tasks, which the enable paths skip as they are\nnever scheduled through SCX. It is also an rcu_dereference_protected()\nthat expects @p's pi_lock or rq lock, which neither wrapper holds.\nPassing NULL to scx_error() reaches scx_vexit(), which dereferences\nsch->exit_info, oopsing the kernel.\n\nOne concrete trigger exercised while developing the fix: a\nBPF_PROG_TYPE_SYSCALL program calling the select_cpu_and wrapper on an\nexited-but-not-reaped task while a sub-scheduler was attached (its pid\nstays findable while the zombie is unreaped; faulting instruction is\nthe scx_vexit() prologue \"mov r15,[rdi+0x398]\" with RDI=NULL and 0x398\nthe offset of sch->exit_info):\n\n  sched_ext: BPF scheduler \"kfunc_subsched_null\" enabled\n  sched_ext: BPF sub-scheduler \"kfunc_subsched_null\" enabled\n  sched_ext: Unassociated program run_select_cpu_ (id 76)\n  BUG: kernel NULL pointer dereference, address: 0000000000000398\n  #PF: supervisor read access in kernel mode\n  #PF: error_code(0x0000) - not-present page\n  Oops: Oops: 0000 [#1] SMP NOPTI\n  CPU: 7 UID: 0 PID: 8201 Comm: kfunc_test_runn Tainted: G W\n  RIP: 0010:scx_vexit+0x25/0xa0\n  Code: ... <4c> 8b bf 98 03 00 00 ...\n  CR2: 0000000000000398\n  Call Trace:\n   <TASK>\n   __scx_exit+0x4f/0x70\n   scx_bpf_select_cpu_and+0xab/0xb0\n   bpf_prog_430ed61a7b66e03a_run_select_cpu_and+0x9c/0xe7\n   ? __x64_sys_bpf+0x2c/0x40\n   bpf_prog_test_run_syscall+0x130/0x2f0\n   __sys_bpf+0x930/0x10d0\n   ? __x64_sys_bpf+0x2c/0x40\n   __x64_sys_bpf+0x2c/0x40\n   do_syscall_64+0xbc/0x460\n   entry_SYSCALL_64_after_hwframe+0x76/0x7e\n   </TASK>\n\nRead @p's scheduler under RCU instead, which the wrappers can do from\ntheir guard(rcu)(): fault it when it can be determined, and when it\ncan't be determined -- @p is a task past sched_ext_dead() or an idle\ntask -- there is nothing obviously wrong to report, so just refuse the\ncall as before without faulting any scheduler.\n\nThese COMPAT wrappers are scheduled for eventual removal once the\ndeprecation grace period elapses, but until then -- and regardless of\ntheir removal timeline -- they must not oops the kernel on a task they\nare handed."
    }
  ],
  "lastModified": "2026-10-06T09:18:08.857",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}