Junglewise Threat Intelligence

CVE-2026-74405: Linux kernel OPP race condition in addition and lookup

CVE-2026-74405 · Severity: high · CVSS 7.8 · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Operating Performance Points (OPP) subsystem manages CPU frequency and power settings. A race condition between adding new frequency points and looking them up can allow concurrent operations to access uninitialized memory structures, leading to memory corruption and system instability. This could cause kernel crashes or unpredictable behavior on systems managing dynamic CPU frequency scaling.

Technical details

The vulnerability is a race condition in the OPP core (drivers/opp/core.c) between dev_pm_opp_add_dynamic() and dev_pm_opp_find_freq_exact() functions. The root cause is that a new OPP object is added to a shared linked list via list_add() before its reference counter (kref) is initialized. A concurrent lookup thread can find the not-yet-initialized OPP, increment its reference count via kref_get(), and later trigger undefined behavior when kref_put_mutex() is called, resulting in refcount corruption and potential premature object free. The fix moves kref initialization and opp_table assignment to occur before list_add(), ensuring any concurrent observer sees a fully initialized object. No special privileges or user interaction are required; the vulnerability is triggered by normal concurrent kernel operations. Patch is available in upstream commit f5e1cc9a284bff2510981643a5bca4bc4c21b81a.

Affected products

  • Linux Linux Kernel 2.6.11 through 7.2 (multiple stable series affected)

Timeline

  • 2026-08-15: disclosed
  • 2026-04-27: patched: Fix commit authored 2026-04-27; released in stable kernels 2026-07-24

References

Related threats