CVE-2026-64373: cpufreq: Fix hotplug-suspend race during reboot

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:49:50 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072523-CVE-2026-64373-2ee3@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

cpufreq: Fix hotplug-suspend race during reboot

During system reboot, cpufreq_suspend() is called via the
kernel_restart() -> device_shutdown() path. Unlike the normal system
suspend path, the reboot path does not call freeze_processes(), so
userspace processes and kernel threads remain active.

This allows CPU hotplug operations to run concurrently with
cpufreq_suspend(). The original code has no synchronization with CPU
hotplug, leading to a race condition where governor_data can be freed
by the hotplug path while cpufreq_suspend() is still accessing it,
resulting in a null pointer dereference:

  Unable to handle kernel NULL pointer dereference
  Call Trace:
   do_kernel_fault+0x28/0x3c
   cpufreq_suspend+0xdc/0x160
   device_shutdown+0x18/0x200
   kernel_restart+0x40/0x80
   arm64_sys_reboot+0x1b0/0x200

Fix this by adding cpus_read_lock()/cpus_read_unlock() to
cpufreq_suspend() to block CPU hotplug operations while suspend is in
progress.

[ rjw: Changelog edits ]

The Linux kernel CVE team has assigned CVE-2026-64373 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 5.10.261 with commit 6d5dd354c37abaf4d60400c55c71f23ba2b33639
	Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 5.15.212 with commit 9103078c7b3091a2fbb52af176f95982ee7dd7f8
	Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 6.1.178 with commit cd4524ff6567fa4458a5bec4b017105e671d393e
	Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 6.6.145 with commit 73255d702c7560185fd5951aadcf7eb057c2f453
	Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 6.12.96 with commit a0ef2fc89d28ca62923376c4b8ffaa57136a36be
	Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 6.18.39 with commit 6e175c00c62dca3d91b987015808b5d52e8db2b4
	Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 7.1.4 with commit a0106b41f9a724868d390b8b3b4ea5ca0e04ea53
	Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 7.2-rc1 with commit a9029dd55696c651ee46912afa2a166fa456bb3e
	Issue introduced in 4.4.198 with commit 8bfa06ea6e81bf08d2132d7e70c2b5313b34caf8
	Issue introduced in 4.9.198 with commit 7ccf3b8b7a12dc9da158c2e699c36d04b2496944
	Issue introduced in 4.14.151 with commit 5f466713989250938624afa79dc33bae20920700
	Issue introduced in 4.19.81 with commit 89ab39da1452d272007acc5912d4008047b86706
	Issue introduced in 5.3.8 with commit cb4b4601f910c78d2b49f637a12ef98b41cb76a9

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64373
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/cpufreq/cpufreq.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/6d5dd354c37abaf4d60400c55c71f23ba2b33639
	https://git.kernel.org/stable/c/9103078c7b3091a2fbb52af176f95982ee7dd7f8
	https://git.kernel.org/stable/c/cd4524ff6567fa4458a5bec4b017105e671d393e
	https://git.kernel.org/stable/c/73255d702c7560185fd5951aadcf7eb057c2f453
	https://git.kernel.org/stable/c/a0ef2fc89d28ca62923376c4b8ffaa57136a36be
	https://git.kernel.org/stable/c/6e175c00c62dca3d91b987015808b5d52e8db2b4
	https://git.kernel.org/stable/c/a0106b41f9a724868d390b8b3b4ea5ca0e04ea53
	https://git.kernel.org/stable/c/a9029dd55696c651ee46912afa2a166fa456bb3e