Executive brief
The Linux kernel's ACPI processor module failed to properly clean up a CPU frequency scaling notifier during initialization errors. If the processor driver initialization failed partway through startup, the cpufreq notifier would remain registered in memory, potentially causing resource leaks or unexpected behavior in CPU power management.
Technical details
This is a resource cleanup bug in the ACPI processor driver (drivers/acpi/processor_driver.c). The acpi_processor_driver_init() function registers a cpufreq policy notifier early in initialization, but the error handling path did not unregister it if subsequent driver_register() or cpuhp_setup_state() calls failed. The fix adds conditional unregistration of the cpufreq notifier in the error path, mirroring the cleanup done during module exit. No authentication or network access is required; the issue is triggered only if module initialization encounters an error. This is a low-severity fix addressing a resource leak rather than a security vulnerability.
Affected products
- Linux Linux kernel multiple versions (patch backported across 2.6.11 through 7.2)
Timeline
- 2026-09-17: disclosed: CVE-2026-90364 published
- 2026-07-31: patched: Fix committed to mainline by Rafael J. Wysocki
- 2026-09-14: patched: Backported to stable branches