Description
In the Linux kernel, the following vulnerability has been resolved:

cpufreq: apple-soc: Fix OPP table cleanup

apple_soc_cpufreq_init() adds OPP tables from firmware, but
some failure paths do not remove them. The driver also uses
dev_pm_opp_remove_all_dynamic(), which is not the right cleanup
helper for OPP tables loaded from firmware.

Use the cpumask OPP helper after the policy CPU mask has been
populated. Pair it with the matching cpumask remove helper on
failure paths and in apple_soc_cpufreq_exit(). This also removes
the separate dev_pm_opp_set_sharing_cpus() call, as the cpumask
helper loads the DT OPP tables for all CPUs in the policy.
Published: 2026-09-11
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak
Action: Patch
AI Analysis

Impact

The vulnerability is a memory leak caused by incomplete cleanup of operating‑point tables in the Linux kernel’s apple‑soc cpufreq driver. With the driver loading firmware‑supplied OPP tables, failure paths fail to remove entries and an incorrect helper is used for firmware‑loaded entries, leaving stale tables resident in memory. The leak can accumulate over time, potentially exhausting kernel memory and degrading system stability, but it does not affect confidentiality, integrity, or authentication.

Affected Systems

The apple‑soc cpufreq driver is part of the Linux kernel. Any kernel release that includes the unpatched driver is affected; specific kernel versions are not enumerated in the CVE data, so all such releases remain at risk.

Risk and Exploitability

The CVSS score of 2.3 signals low severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability requires a local kernel interaction during driver initialization and can be triggered by a driver load failure, such as a reboot or module reload. No remote attack vector or privilege escalation is documented, and it is not listed in the CISA KEV catalog, limiting the risk mainly to local resource exhaustion.

Generated by OpenCVE AI on September 13, 2026 at 06:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Linux kernel that includes the apple‑soc cpufreq driver patch
  • Reboot the system to load the updated kernel and driver
  • Verify that no stale OPP entries remain by monitoring kernel memory consumption

Generated by OpenCVE AI on September 13, 2026 at 06:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 2.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Low


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cpufreq: apple-soc: Fix OPP table cleanup apple_soc_cpufreq_init() adds OPP tables from firmware, but some failure paths do not remove them. The driver also uses dev_pm_opp_remove_all_dynamic(), which is not the right cleanup helper for OPP tables loaded from firmware. Use the cpumask OPP helper after the policy CPU mask has been populated. Pair it with the matching cpumask remove helper on failure paths and in apple_soc_cpufreq_exit(). This also removes the separate dev_pm_opp_set_sharing_cpus() call, as the cpumask helper loads the DT OPP tables for all CPUs in the policy.
Title cpufreq: apple-soc: Fix OPP table cleanup
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:44:41.072Z

Reserved: 2026-09-11T19:38:34.727Z

Link: CVE-2026-89572

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:41.270

Modified: 2026-09-11T20:19:41.270

Link: CVE-2026-89572

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-11T19:44:41Z

Links: CVE-2026-89572 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T06:45:18Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime