SB20260727196 - Race condition in Linux kernel cpufreq driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-64373)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in cpufreq_suspend() when rebooting the system while cpu hotplug operations run concurrently. A local user can trigger a reboot while concurrent cpu hotplug activity causes governor_data to be freed during access to cause a denial of service.
The issue can result in a kernel null pointer dereference during the reboot path because processes and kernel threads remain active.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/6d5dd354c37abaf4d60400c55c71f23ba2b33639
- https://git.kernel.org/stable/c/6e175c00c62dca3d91b987015808b5d52e8db2b4
- https://git.kernel.org/stable/c/73255d702c7560185fd5951aadcf7eb057c2f453
- https://git.kernel.org/stable/c/9103078c7b3091a2fbb52af176f95982ee7dd7f8
- https://git.kernel.org/stable/c/a0106b41f9a724868d390b8b3b4ea5ca0e04ea53
- https://git.kernel.org/stable/c/a0ef2fc89d28ca62923376c4b8ffaa57136a36be
- https://git.kernel.org/stable/c/a9029dd55696c651ee46912afa2a166fa456bb3e
- https://git.kernel.org/stable/c/cd4524ff6567fa4458a5bec4b017105e671d393e