In the Linux kernel, the following vulnerability has been resolved: cpufreq: initialize policy...

zetlyn/cve-ghsa vulnerability ghsa GHSA-73ff-5qgw-vhj7 cve CVE-2026-97904 known 2026-09-25

https://github.com/advisories/GHSA-73ff-5qgw-vhj7

Properties

severityunknown
receipt
Source
GitHub advisories
Said since
2026-09-26 15:00 UTC
Last answered
2026-10-06 13:46 UTC
Original
open at the source

This source has not kept a receipt for this claim yet. The next update that reads it will.

Text

In the Linux kernel, the following vulnerability has been resolved: cpufreq: initialize policy... In the Linux kernel, the following vulnerability has been resolved: cpufreq: initialize policy rwsem before sysfs publication cpufreq_policy_alloc() initializes policy->rwsem after kobject_init_and_add() has created the policy sysfs directory and its default attributes. A sysfs access can therefore reach a policy callback before the semaphore has been initialized. Initialize policy->rwsem before publishing the policy kobject so sysfs callbacks always see an initialized semaphore.