CVE-2026-89992
8.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
cpuidle: dt_idle_genpd: kfree() the original name allocation
dt_idle_pd_alloc() kasprintf()s the full node path, then points pd->name at kbasename() of that string. dt_idle_pd_free() kfree()s pd->name, which is no longer the start of the allocation.
Copy the basename instead.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 9d976d6721dfb525b81ce981e1363c70c0975aab < 1312ae33b91430ec99e69cd3d47f0e50a4ebf54b | affected |
| Linux | Linux | 9d976d6721dfb525b81ce981e1363c70c0975aab < a38caa9ed0d5c61c17d88393b14b292199289c1f | affected |
| Linux | Linux | 9d976d6721dfb525b81ce981e1363c70c0975aab < 09d002c8fb0261d35ce9d8a705de5db034ee90b8 | affected |
| Linux | Linux | 9d976d6721dfb525b81ce981e1363c70c0975aab < b519dfce1998c323e54a56f911cf708d9ba0e076 | affected |
| Linux | Linux | 9d976d6721dfb525b81ce981e1363c70c0975aab < 3394c7ba23336bdb7ece29127130fd01731d42d8 | affected |
| Linux | Linux | 9d976d6721dfb525b81ce981e1363c70c0975aab < 2b0ac85512b7f67479127b2713254490662eb13d | affected |
| Linux | Linux | 5.18 | affected |
| Linux | Linux | 0 < 5.18 | unaffected |
| Linux | Linux | 6.1.188 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.157 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/1312ae33b91430ec99e69cd3d47f0e50a4ebf54b
- https://git.kernel.org/stable/c/a38caa9ed0d5c61c17d88393b14b292199289c1f
- https://git.kernel.org/stable/c/09d002c8fb0261d35ce9d8a705de5db034ee90b8
- https://git.kernel.org/stable/c/b519dfce1998c323e54a56f911cf708d9ba0e076
- https://git.kernel.org/stable/c/3394c7ba23336bdb7ece29127130fd01731d42d8
- https://git.kernel.org/stable/c/2b0ac85512b7f67479127b2713254490662eb13d
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.