Executive brief
A vulnerability was identified in the Linux kernel's Processor Clocking Control (PCC) driver. This component manages CPU frequency scaling on certain hardware. An exploit could lead to a system crash or potentially allow an attacker to gain elevated privileges by triggering memory corruption during hardware initialization.
Technical details
The vulnerability is located in pcc_cpufreq_do_osc() within drivers/cpufreq/pcc-cpufreq.c. The function calls acpi_evaluate_object() twice for two-phase _OSC negotiation. After the first call, output.pointer is freed, but output.length remains non-zero. Because acpi_evaluate_object() interprets a non-zero length with a non-NULL pointer as an existing buffer, the second call performs a write to the previously freed memory (use-after-free). This is followed by a second kfree() on the same pointer, resulting in a double-free. The fix involves resetting output.pointer to NULL and output.length to ACPI_ALLOCATE_BUFFER between calls.
Affected products
- Linux Linux 2.6.34 to 6.13
Timeline
- 2026-04-16: patched: Initial patch proposed by developer
- 2026-07-25: advisory: CVE-2026-64372 published
References
- https://git.kernel.org/stable/c/0e3c739a2f6fc1de5b19a8839ab80696b9cb2a29
- https://git.kernel.org/stable/c/266d3dd8b757b48a576e90f018b51f7b7563cc32
- https://git.kernel.org/stable/c/5cdb25f144b101083d8bf3fd023ad87fbe6850d7
- https://git.kernel.org/stable/c/632666a63116d8061c62a988d1ca39dcd6d27c9b
- https://git.kernel.org/stable/c/6ba6f6783be2ffeb2cbcdc9321c4b9f708f796f7
- https://git.kernel.org/stable/c/8e454e9d0bc03446d610ee49abec9dfd424f6541
- https://git.kernel.org/stable/c/982c9f92d57bda2b769851ff6d90d43dcf5f3734