CVE-2026-64373: cpufreq: Fix hotplug-suspend race during reboot
Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:49:50 +0200
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026072523-CVE-2026-64373-2ee3@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: cpufreq: Fix hotplug-suspend race during reboot During system reboot, cpufreq_suspend() is called via the kernel_restart() -> device_shutdown() path. Unlike the normal system suspend path, the reboot path does not call freeze_processes(), so userspace processes and kernel threads remain active. This allows CPU hotplug operations to run concurrently with cpufreq_suspend(). The original code has no synchronization with CPU hotplug, leading to a race condition where governor_data can be freed by the hotplug path while cpufreq_suspend() is still accessing it, resulting in a null pointer dereference: Unable to handle kernel NULL pointer dereference Call Trace: do_kernel_fault+0x28/0x3c cpufreq_suspend+0xdc/0x160 device_shutdown+0x18/0x200 kernel_restart+0x40/0x80 arm64_sys_reboot+0x1b0/0x200 Fix this by adding cpus_read_lock()/cpus_read_unlock() to cpufreq_suspend() to block CPU hotplug operations while suspend is in progress. [ rjw: Changelog edits ] The Linux kernel CVE team has assigned CVE-2026-64373 to this issue. Affected and fixed versions =========================== Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 5.10.261 with commit 6d5dd354c37abaf4d60400c55c71f23ba2b33639 Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 5.15.212 with commit 9103078c7b3091a2fbb52af176f95982ee7dd7f8 Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 6.1.178 with commit cd4524ff6567fa4458a5bec4b017105e671d393e Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 6.6.145 with commit 73255d702c7560185fd5951aadcf7eb057c2f453 Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 6.12.96 with commit a0ef2fc89d28ca62923376c4b8ffaa57136a36be Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 6.18.39 with commit 6e175c00c62dca3d91b987015808b5d52e8db2b4 Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 7.1.4 with commit a0106b41f9a724868d390b8b3b4ea5ca0e04ea53 Issue introduced in 5.4 with commit 65650b35133ff20f0c9ef0abd5c3c66dbce3ae57 and fixed in 7.2-rc1 with commit a9029dd55696c651ee46912afa2a166fa456bb3e Issue introduced in 4.4.198 with commit 8bfa06ea6e81bf08d2132d7e70c2b5313b34caf8 Issue introduced in 4.9.198 with commit 7ccf3b8b7a12dc9da158c2e699c36d04b2496944 Issue introduced in 4.14.151 with commit 5f466713989250938624afa79dc33bae20920700 Issue introduced in 4.19.81 with commit 89ab39da1452d272007acc5912d4008047b86706 Issue introduced in 5.3.8 with commit cb4b4601f910c78d2b49f637a12ef98b41cb76a9 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64373 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/cpufreq/cpufreq.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/6d5dd354c37abaf4d60400c55c71f23ba2b33639 https://git.kernel.org/stable/c/9103078c7b3091a2fbb52af176f95982ee7dd7f8 https://git.kernel.org/stable/c/cd4524ff6567fa4458a5bec4b017105e671d393e https://git.kernel.org/stable/c/73255d702c7560185fd5951aadcf7eb057c2f453 https://git.kernel.org/stable/c/a0ef2fc89d28ca62923376c4b8ffaa57136a36be https://git.kernel.org/stable/c/6e175c00c62dca3d91b987015808b5d52e8db2b4 https://git.kernel.org/stable/c/a0106b41f9a724868d390b8b3b4ea5ca0e04ea53 https://git.kernel.org/stable/c/a9029dd55696c651ee46912afa2a166fa456bb3e