CVE-2026-93069

Summary

In the Linux kernel, the following vulnerability has been resolved:

OPP: Fix cleanup ordering

Commit 173e02d67494 ("OPP: Initialize scope-based pointers inline") added initialization for all pointers. In some cases, the ordering was changed so that *opp_table was initialized after *opp. This also changes the order of the registered cleanup functions.

When the cleanup happens, this can cause use-after-free errors when the last reference is released and the release function _opp_kref_release tries to access the already freed opp->opp_table.

Initialize *opp_table before *opp again to fix this and ensure the correct cleanup order.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux173e02d674946ff3ef8da7f44a9d5b820b9af21c < f0c4b7ca24d2e2618a70826881d69b237e36bcc0affected
LinuxLinux173e02d674946ff3ef8da7f44a9d5b820b9af21c < ce46fede7792cedd247e34b48bc8a02eb90c7848affected
LinuxLinux6.19affected
LinuxLinux0 < 6.19unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References