Junglewise Threat Intelligence

CVE-2026-64372: Linux Kernel use-after-free in PCC cpufreq driver

CVE-2026-64372 · Severity: info · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Processor Clocking Control (PCC) driver. This component manages CPU frequency scaling on certain hardware. An exploit could lead to a system crash or potentially allow an attacker to gain elevated privileges by triggering memory corruption during hardware initialization.

Technical details

The vulnerability is located in pcc_cpufreq_do_osc() within drivers/cpufreq/pcc-cpufreq.c. The function calls acpi_evaluate_object() twice for two-phase _OSC negotiation. After the first call, output.pointer is freed, but output.length remains non-zero. Because acpi_evaluate_object() interprets a non-zero length with a non-NULL pointer as an existing buffer, the second call performs a write to the previously freed memory (use-after-free). This is followed by a second kfree() on the same pointer, resulting in a double-free. The fix involves resetting output.pointer to NULL and output.length to ACPI_ALLOCATE_BUFFER between calls.

Affected products

  • Linux Linux 2.6.34 to 6.13

Timeline

  • 2026-04-16: patched: Initial patch proposed by developer
  • 2026-07-25: advisory: CVE-2026-64372 published

References