CVE-2026-64372: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:49:49 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072523-CVE-2026-64372-794b@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

cpufreq: pcc: fix use-after-free and double free in _OSC evaluation

pcc_cpufreq_do_osc() calls acpi_evaluate_object() twice for the
two-phase _OSC negotiation. Between the two calls it freed
output.pointer but left output.length unchanged. Since
acpi_evaluate_object() treats a non-zero length with a non-NULL
pointer as an existing buffer to write into, the second call wrote
into freed memory (use-after-free). The subsequent kfree(output.pointer)
at out_free then freed the same pointer a second time (double free).

Reset output.pointer to NULL and output.length to ACPI_ALLOCATE_BUFFER
after freeing the first result, so ACPICA allocates a fresh buffer for
each phase independently.

The Linux kernel CVE team has assigned CVE-2026-64372 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 5.10.261 with commit 8e454e9d0bc03446d610ee49abec9dfd424f6541
	Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 5.15.212 with commit 632666a63116d8061c62a988d1ca39dcd6d27c9b
	Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 6.1.178 with commit 5cdb25f144b101083d8bf3fd023ad87fbe6850d7
	Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 6.6.145 with commit 982c9f92d57bda2b769851ff6d90d43dcf5f3734
	Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 6.12.96 with commit a36ca93a8ba57464e521d70a337d37f069064111
	Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 6.18.39 with commit 6ba6f6783be2ffeb2cbcdc9321c4b9f708f796f7
	Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 7.1.4 with commit 0e3c739a2f6fc1de5b19a8839ab80696b9cb2a29
	Issue introduced in 2.6.34 with commit 0f1d683fb35d6c6f49ef696c95757f3970682a0e and fixed in 7.2-rc1 with commit 266d3dd8b757b48a576e90f018b51f7b7563cc32

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64372
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/cpufreq/pcc-cpufreq.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/8e454e9d0bc03446d610ee49abec9dfd424f6541
	https://git.kernel.org/stable/c/632666a63116d8061c62a988d1ca39dcd6d27c9b
	https://git.kernel.org/stable/c/5cdb25f144b101083d8bf3fd023ad87fbe6850d7
	https://git.kernel.org/stable/c/982c9f92d57bda2b769851ff6d90d43dcf5f3734
	https://git.kernel.org/stable/c/a36ca93a8ba57464e521d70a337d37f069064111
	https://git.kernel.org/stable/c/6ba6f6783be2ffeb2cbcdc9321c4b9f708f796f7
	https://git.kernel.org/stable/c/0e3c739a2f6fc1de5b19a8839ab80696b9cb2a29
	https://git.kernel.org/stable/c/266d3dd8b757b48a576e90f018b51f7b7563cc32