CVE-2026-64372: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
cpufreq: pcc: fix use-after-free and double free in OSC evaluation
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1 - Upgrade
Upgrade
Linux kernel (ACPICA)to a version that resolves this vulnerability.Fixed in resolved - Compensating control
As a mitigation, ensure the ACPICA/A C P I _OSC evaluation path cannot be triggered by untrusted firmware inputs until the kernel fix is applied.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates local access and low privileges are required. No user interaction is required.
What security impact could successful exploitation have?
The CVSS vector rates confidentiality, integrity, and availability impacts as high. The flaw involves both use-after-free and double-free behavior in the kernel.
Which systems are identified as affected?
The provided data identifies the Linux kernel and Microsoft azl3 kernel 6.6.144.1-1. No broader version range or configuration criteria is provided.
How is the vulnerable memory handling corrected?
After the first _OSC evaluation result is freed, the fix resets output.pointer to NULL and output.length to ACPI_ALLOCATE_BUFFER. This causes ACPICA to allocate a new buffer for the second evaluation phase rather than writing to or freeing the prior buffer again.