Junglewise Threat Intelligence

CVE-2026-64373: Linux Kernel race condition in cpufreq_suspend during reboot

CVE-2026-64373 · Severity: info · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's power management component can cause a system crash during reboot. When a computer is restarting, certain background processes managing processor speed and hardware changes can conflict, leading to a 'null pointer dereference' that halts the system. This primarily impacts system availability during the shutdown or restart process.

Technical details

A race condition exists in cpufreq_suspend() during the reboot path (kernel_restart -> device_shutdown). Unlike standard system suspend, the reboot path does not call freeze_processes(), allowing CPU hotplug operations to run concurrently with cpufreq_suspend(). This lack of synchronization allows governor_data to be freed by a hotplug event while still being accessed by cpufreq_suspend(), resulting in a null pointer dereference. The fix introduces cpus_read_lock() and cpus_read_unlock() to properly synchronize these operations. This is a local availability issue requiring specific timing during system power state transitions.

Affected products

  • Linux Linux 65650b35133f to 6d5dd354c37a, 9103078c7b30, cd4524ff6567, 73255d702c75, a0ef2fc89d28, 6e175c00c62d, a0106b41f9a7, a9029dd55696

Timeline

  • 2026-07-25: advisory: CVE-2026-64373 published by NVD
  • 2026-07-24: patched: Fix committed to various Linux stable branches

References