CVE-2026-64372: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:49:49 +0200
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026072523-CVE-2026-64372-794b@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation pcc_cpufreq_do_osc() calls acpi_evaluate_object() twice for the two-phase _OSC negotiation. Between the two calls it freed output.pointer but left output.length unchanged. Since acpi_evaluate_object() treats a non-zero length with a non-NULL pointer as an existing buffer to write into, the second call wrote into freed memory (use-after-free). The subsequent kfree(output.pointer) at out_free then freed the same pointer a second time (double free). Reset output.pointer to NULL and output.length to ACPI_ALLOCATE_BUFFER after freeing the first result, so ACPICA allocates a fresh buffer for each phase independently. The Linux kernel CVE team has assigned CVE-2026-64372 to this issue. Affected and fixed versions =========================== Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 5.10.261 with commit 8e454e9d0bc03446d610ee49abec9dfd424f6541 Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 5.15.212 with commit 632666a63116d8061c62a988d1ca39dcd6d27c9b Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 6.1.178 with commit 5cdb25f144b101083d8bf3fd023ad87fbe6850d7 Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 6.6.145 with commit 982c9f92d57bda2b769851ff6d90d43dcf5f3734 Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 6.12.96 with commit a36ca93a8ba57464e521d70a337d37f069064111 Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 6.18.39 with commit 6ba6f6783be2ffeb2cbcdc9321c4b9f708f796f7 Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 7.1.4 with commit 0e3c739a2f6fc1de5b19a8839ab80696b9cb2a29 Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 7.2-rc1 with commit 266d3dd8b757b48a576e90f018b51f7b7563cc32 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64372 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/cpufreq/pcc-cpufreq.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/8e454e9d0bc03446d610ee49abec9dfd424f6541 https://git.kernel.org/stable/c/632666a63116d8061c62a988d1ca39dcd6d27c9b https://git.kernel.org/stable/c/5cdb25f144b101083d8bf3fd023ad87fbe6850d7 https://git.kernel.org/stable/c/982c9f92d57bda2b769851ff6d90d43dcf5f3734 https://git.kernel.org/stable/c/a36ca93a8ba57464e521d70a337d37f069064111 https://git.kernel.org/stable/c/6ba6f6783be2ffeb2cbcdc9321c4b9f708f796f7 https://git.kernel.org/stable/c/0e3c739a2f6fc1de5b19a8839ab80696b9cb2a29 https://git.kernel.org/stable/c/266d3dd8b757b48a576e90f018b51f7b7563cc32