Executive brief
A vulnerability in the Linux kernel's power management component can cause a system crash during reboot. When a computer is restarting, certain background processes managing processor speed and hardware changes can conflict, leading to a 'null pointer dereference' that halts the system. This primarily impacts system availability during the shutdown or restart process.
Technical details
A race condition exists in cpufreq_suspend() during the reboot path (kernel_restart -> device_shutdown). Unlike standard system suspend, the reboot path does not call freeze_processes(), allowing CPU hotplug operations to run concurrently with cpufreq_suspend(). This lack of synchronization allows governor_data to be freed by a hotplug event while still being accessed by cpufreq_suspend(), resulting in a null pointer dereference. The fix introduces cpus_read_lock() and cpus_read_unlock() to properly synchronize these operations. This is a local availability issue requiring specific timing during system power state transitions.
Affected products
- Linux Linux 65650b35133f to 6d5dd354c37a, 9103078c7b30, cd4524ff6567, 73255d702c75, a0ef2fc89d28, 6e175c00c62d, a0106b41f9a7, a9029dd55696
Timeline
- 2026-07-25: advisory: CVE-2026-64373 published by NVD
- 2026-07-24: patched: Fix committed to various Linux stable branches
References
- https://git.kernel.org/stable/c/6d5dd354c37abaf4d60400c55c71f23ba2b33639
- https://git.kernel.org/stable/c/6e175c00c62dca3d91b987015808b5d52e8db2b4
- https://git.kernel.org/stable/c/73255d702c7560185fd5951aadcf7eb057c2f453
- https://git.kernel.org/stable/c/9103078c7b3091a2fbb52af176f95982ee7dd7f8
- https://git.kernel.org/stable/c/a0106b41f9a724868d390b8b3b4ea5ca0e04ea53
- https://git.kernel.org/stable/c/a0ef2fc89d28ca62923376c4b8ffaa57136a36be
- https://git.kernel.org/stable/c/a9029dd55696c651ee46912afa2a166fa456bb3e