-

CVE-2026-97905

cpufreq: zero-initialize policy cpumask before sysfs publication

In the Linux kernel, the following vulnerability has been resolved:

cpufreq: zero-initialize policy cpumask before sysfs publication

cpufreq_policy_alloc() allocates policy->cpus with alloc_cpumask_var(),
i.e. without __GFP_ZERO, unlike the sibling related_cpus and real_cpus
masks. With CONFIG_CPUMASK_OFFSTACK=y the mask is a separate
kmalloc_node() allocation, so its bitmap holds whatever the slab allocator
left behind:

  cpufreq_online()
    cpufreq_policy_alloc()
      alloc_cpumask_var(&policy->cpus)    /* bitmap is uninitialized */
      kobject_init_and_add()              /* policy%u/ appears in sysfs */
    cpufreq_policy_online()
      cpumask_copy(policy->cpus, cpumask_of(cpu))  /* first valid value */

This leaves a window in which the sysfs attributes are already reachable
while policy->cpus is still garbage. show()/store() gate on
policy_is_inactive(), i.e. cpumask_empty(policy->cpus), so a non-zero
bitmap makes them run the attribute callbacks on a policy that is not
initialized yet.

Fix this by using zalloc_cpumask_var() for policy->cpus.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 2fc3384dc75bf7333384c7a16d12c796f61c3f56
Version < e13370c5b549712f49f80234df249303381c53b4
Status affected
Version 2fc3384dc75bf7333384c7a16d12c796f61c3f56
Version < e807920031ca32b668f9e7a1efbd21858f03d64b
Status affected
Version 2fc3384dc75bf7333384c7a16d12c796f61c3f56
Version < ca52482508b3ac9febe74ca4f732647d394727b8
Status affected
Version 2fc3384dc75bf7333384c7a16d12c796f61c3f56
Version < 06f273d29e5e0fe5c775a65c563fbeed8cd94c7a
Status affected
Version 2fc3384dc75bf7333384c7a16d12c796f61c3f56
Version < 0de2f3918fbbbb767e7e716178194b66560dd12a
Status affected
Version 2fc3384dc75bf7333384c7a16d12c796f61c3f56
Version < 6e166b9281dec98aed19213a84235250e5fdb081
Status affected
Version 2fc3384dc75bf7333384c7a16d12c796f61c3f56
Version < bbc0472d2270bf732142ca71579d6ede636174ed
Status affected
Version 2fc3384dc75bf7333384c7a16d12c796f61c3f56
Version < 54d37bcf2f497140b9207968557ddb484058e749
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.2
Status affected
Version 0
Version < 4.2
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.088
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0de2f3918fbbbb767e7e716178194b66560dd12a
https://git.kernel.org/stable/c/6e166b9281dec98aed19213a84235250e5fdb081
https://git.kernel.org/stable/c/bbc0472d2270bf732142ca71579d6ede636174ed
https://git.kernel.org/stable/c/54d37bcf2f497140b9207968557ddb484058e749
https://git.kernel.org/stable/c/06f273d29e5e0fe5c775a65c563fbeed8cd94c7a
https://git.kernel.org/stable/c/ca52482508b3ac9febe74ca4f732647d394727b8
https://git.kernel.org/stable/c/e13370c5b549712f49f80234df249303381c53b4
https://git.kernel.org/stable/c/e807920031ca32b668f9e7a1efbd21858f03d64b