← Volver al buscador de CVEs

CVE-2026-43401

Linux Kernel

Descripción

In the Linux kernel, the following vulnerability has been resolved: cpufreq: intel_pstate: Fix NULL pointer dereference in update_cpu_qos_request() The update_cpu_qos_request() function attempts to initialize the -freq- variable by dereferencing -cpudata- before verifying if the -policy- is valid. This issue occurs on systems booted with the -nosmt- parameter, where all_cpu_data[cpu] is NULL for the SMT sibling threads. As a result, any call to update_qos_requests() will result in a NULL pointer dereference as the code will attempt to access pstate.turbo_freq using the NULL cpudata pointer. Also, pstate.turbo_freq may be updated by intel_pstate_get_hwp_cap() after initializing the -freq- variable, so it is better to defer the -freq- until intel_pstate_get_hwp_cap() has been called. Fix this by deferring the -freq- assignment until after the policy and driver_data have been validated. [ rjw: Added one paragraph to the changelog ]

CVSS 5.5EPSS 0.121%Riesgo 0.56
Ver fuente
Publicación
2026-05-08 15:16:51
Versiones afectadas
unknown
Tipo
Core software
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Sistemas operativos
Linux