Description
In the Linux kernel, the following vulnerability has been resolved:

cpufreq: apple-soc: Fix OPP table cleanup

apple_soc_cpufreq_init() adds OPP tables from firmware, but
some failure paths do not remove them. The driver also uses
dev_pm_opp_remove_all_dynamic(), which is not the right cleanup
helper for OPP tables loaded from firmware.

Use the cpumask OPP helper after the policy CPU mask has been
populated. Pair it with the matching cpumask remove helper on
failure paths and in apple_soc_cpufreq_exit(). This also removes
the separate dev_pm_opp_set_sharing_cpus() call, as the cpumask
helper loads the DT OPP tables for all CPUs in the policy.
Published: 2026-09-11
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak / Resource Exhaustion
Action: Patch
AI Analysis

Impact

The apple‑soc cpufreq driverP) tables that are loaded from firmware when driver initialization fails, leading to stale kernel memory entries and resource exhaustion. This flaw does not grant direct confidentiality or integrity violations; it merely depletes system resources until the driver is reloaded or the machine is rebooted.

Affected Systems

All Linux kernel releases that contain the unpatched apple‑soc cpufreq driver are subject to this issue. Any kernel version prior to the patch remains at risk until a newer kernel incorporating the fix is installed.

Risk and Exploitability

The CVSS score of 2.3 indicates low severity and the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability requires local kernel interaction during driver initialization; no remote attack vector or privilege escalation is documented. The attack vector is inferred driver load and cleanup paths. Since the issue is not listed in the CISA KEV catalog, the overall risk is that a malicious local user or process could deplete kernel resources by triggering repeated failed initialization or unloads of the driver.

Generated by OpenCVE AI on September 15, 2026 at 21:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel that includes the apple‑soc cpufreq driver patch
  • Reboot the system so the updated kernel and driver are loaded
  • Apply a backported patch to the apple‑soc cpufreq driver in the current kernel if an immediate kernel upgrade is unavailable

Generated by OpenCVE AI on September 15, 2026 at 21:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Low


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix OPP table cleanup apple_soc_cpufreq_init() adds OPP tables from firmware, but some failure paths do not remove them. The driver also uses dev_pm_opp_remove_all_dynamic(), which is not the right cleanup helper for OPP tables loaded from firmware. Use the cpumask OPP helper after the policy CPU mask has been populated. Pair it with the matching cpumask remove helper on failure paths and in apple_soc_cpufreq_exit(). This also removes the separate dev_pm_opp_set_sharing_cpus() call, as the cpumask helper loads the DT OPP tables for all CPUs in the policy.
Title cpufreq: apple-soc: Fix OPP table cleanup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:31.538Z

Reserved: 2026-09-11T19:38:34.727Z

Link: CVE-2026-89572

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:41.270

Modified: 2026-09-21T14:17:23.577

Link: CVE-2026-89572

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-11T19:44:41Z

Links: CVE-2026-89572 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T22:00:17Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime