CVE-2026-64372: cpufreq: pcc: fix use-after-free and double free in _OSC evaluation
cpufreq: pcc: fix use-after-free and double free in OSC evaluation
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1 - Upgrade
Upgrade
Linux kernel (ACPICA)to a version that resolves this vulnerability.Fixed in resolved - Compensating control
As a mitigation, ensure the ACPICA/A C P I _OSC evaluation path cannot be triggered by untrusted firmware inputs until the kernel fix is applied.