Race condition in Linux kernel - CVE-2026-64373
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a race condition in cpufreq_suspend() when rebooting the system while cpu hotplug operations run concurrently. A local user can trigger a reboot while concurrent cpu hotplug activity causes governor_data to be freed during access to cause a denial of service.
The issue can result in a kernel null pointer dereference during the reboot path because processes and kernel threads remain active.
Affected software
Ubuntu
linux (Ubuntu package)
linux-azure (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oracle-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
linux-azure-7.0 (Ubuntu package)
How to mitigate CVE-2026-64373
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-azure (Ubuntu package) - addressed in versions 7.0.0-1011.11, 7.0.0-1014.14
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oracle-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
linux-azure-7.0 (Ubuntu package) - update to 7.0.0-1014.14~24.04.1
External References
- https://git.kernel.org/stable/c/6d5dd354c37abaf4d60400c55c71f23ba2b33639
- https://git.kernel.org/stable/c/6e175c00c62dca3d91b987015808b5d52e8db2b4
- https://git.kernel.org/stable/c/73255d702c7560185fd5951aadcf7eb057c2f453
- https://git.kernel.org/stable/c/9103078c7b3091a2fbb52af176f95982ee7dd7f8
- https://git.kernel.org/stable/c/a0106b41f9a724868d390b8b3b4ea5ca0e04ea53
- https://git.kernel.org/stable/c/a0ef2fc89d28ca62923376c4b8ffaa57136a36be
- https://git.kernel.org/stable/c/a9029dd55696c651ee46912afa2a166fa456bb3e
- https://git.kernel.org/stable/c/cd4524ff6567fa4458a5bec4b017105e671d393e