In the Linux kernel, the following vulnerability has been resolved: cpufreq: initialize policy...
zetlyn/cve-ghsa vulnerability ghsa GHSA-73ff-5qgw-vhj7 cve CVE-2026-97904 known 2026-09-25
https://github.com/advisories/GHSA-73ff-5qgw-vhj7
Properties
| severity | unknownreceipt
This source has not kept a receipt for this claim yet. The next update that reads it will. |
|---|
Text
In the Linux kernel, the following vulnerability has been resolved:
cpufreq: initialize policy...
In the Linux kernel, the following vulnerability has been resolved:
cpufreq: initialize policy rwsem before sysfs publication
cpufreq_policy_alloc() initializes policy->rwsem after
kobject_init_and_add() has created the policy sysfs directory and its
default attributes. A sysfs access can therefore reach a policy callback
before the semaphore has been initialized.
Initialize policy->rwsem before publishing the policy kobject so sysfs
callbacks always see an initialized semaphore.