Description
In the Linux kernel, the following vulnerability has been resolved:

cpufreq: imx6q: fix out-of-bounds write when probed more than once

imx6_soc_volt is allocated fresh on every probe, sized to the number of
ARM OPPs:

imx6_soc_volt = devm_kcalloc(cpu_dev, num, sizeof(*imx6_soc_volt),
GFP_KERNEL);

but it is filled through soc_opp_count, which has static storage and is
never reset. A second bind after an unbind keeps indexing from where the
first one stopped, and writes past the end of the new array.

Unbinding and rebinding the driver on qemu's mcimx6ul-evk, under KASAN:

BUG: KASAN: slab-out-of-bounds in imx6q_cpufreq_probe+0x3b0/0xa34
Write of size 4 at addr c5e90480 by task binder/73
imx6q_cpufreq_probe from platform_probe+0x88/0xe4
platform_probe from really_probe+0x108/0x384
bind_store from kernfs_fop_write_iter+0x1b4/0x28c

The write lands one u32 past the end of the allocation.

soc_opp_count is only read a few lines below the loop that fills it, so it
never needed static storage. Make it a local.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory corruption potentially enabling privilege escalation or remote code execution
Action: Immediate Patch
AI Analysis

Impact

The imx6q cpufreq driver in the Linux kernel allocates an array of voltage entries for each ARM OPP during probe, but it uses a static counter that is never reset. When a second bind occurs after an unbind, the counter continues from its previous value, writing past the newly allocated array’s end and overflowing one 32‑bit element. This out‑of‑bounds write corrupts kernel memory, allowing an attacker who can trigger consecutive probe cycles to overwrite arbitrary kernel addresses and potentially gain elevated privileges or execute arbitrary code. The description indicates that an attacker would need the ability to rebind the driver, which typically requires local access to sysfs or the device tree – this is inferred as the attack vector.

Affected Systems

Systems running the Linux kernel with the imx6q cpufreq driver are affected. The vulnerability is present in any kernel version before the commits referenced in the CVE description. No specific kernel releases are listed, so all implementations that load this driver prior to the patch are potentially impacted.

Risk and Exploitability

The flaw is a classic out‑of‑bounds write (CWE-119/CWE-787). Exploitation requires the ability to bind and unbind the driver more than once, which typically requires local access to device tree or sysfs nodes. The EPSS score is less than 1 % and the issue is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation, yet the severity of the potential kernel corruption warrants prompt patching. It is not explicitly stated that remote exploitation is possible; the information suggests that local privileges are required.

Generated by OpenCVE AI on September 19, 2026 at 15:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the patch for the imx6q cpufreq driver.
  • If using a custom or embedded kernel, rebuild the kernel incorporating the commit that fixes the out‑of‑bounds write.
  • Disable or remove the imx6q cpufreq module if it is not required for system operation.

Generated by OpenCVE AI on September 19, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-787

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cpufreq: imx6q: fix out-of-bounds write when probed more than once imx6_soc_volt is allocated fresh on every probe, sized to the number of ARM OPPs: imx6_soc_volt = devm_kcalloc(cpu_dev, num, sizeof(*imx6_soc_volt), GFP_KERNEL); but it is filled through soc_opp_count, which has static storage and is never reset. A second bind after an unbind keeps indexing from where the first one stopped, and writes past the end of the new array. Unbinding and rebinding the driver on qemu's mcimx6ul-evk, under KASAN: BUG: KASAN: slab-out-of-bounds in imx6q_cpufreq_probe+0x3b0/0xa34 Write of size 4 at addr c5e90480 by task binder/73 imx6q_cpufreq_probe from platform_probe+0x88/0xe4 platform_probe from really_probe+0x108/0x384 bind_store from kernfs_fop_write_iter+0x1b4/0x28c The write lands one u32 past the end of the allocation. soc_opp_count is only read a few lines below the loop that fills it, so it never needed static storage. Make it a local.
Title cpufreq: imx6q: fix out-of-bounds write when probed more than once
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:08:21.295Z

Reserved: 2026-09-11T19:38:34.799Z

Link: CVE-2026-90295

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:26.853

Modified: 2026-09-17T17:17:26.853

Link: CVE-2026-90295

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T15:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write