Description
In the Linux kernel, the following vulnerability has been resolved:

ACPI: processor: Unregister cpufreq notifier on init failure

acpi_processor_driver_init() registers the cpufreq policy notifier before
registering the ACPI processor driver and setting up CPU hotplug state.

If driver_register() or cpuhp_setup_state() fails, the error path only
unregisters the ACPI processor driver and the idle driver. The cpufreq
notifier remains registered even though initialization failed.

Mirror the module exit path on the init failure path and unregister the
cpufreq notifier when it has been registered.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Resource leak that may lead to kernel crash or denial of service
Action: Patch
AI Analysis

Impact

During initialization of the ACPI processor driver in the Linux kernel a cpufreq policy notifier is registered before the driver and CPU hotplug state are fully set up; if either the driver_register or cpuhp_setup_state calls fail the error path cleans up the driver but fails to unregister the cpufreq notifier, leaving it registered with a dangling reference to a partially initialized driver, which may later be invoked by CPU frequency change events and can cause a kernel panic or crash, effectively denying service.

Affected Systems

Linux kernel on all supported distributions and versions, as indicated by the vendor/product entry and the general CPE string. No specific version constraints are provided, so all released kernel branches may be impacted until the fix is integrated.

Risk and Exploitability

The EPSS score of < 1 % indicates that exploitation in the wild is very unlikely and the vulnerability is not listed in CISA KEV; however the flaw can be triggered by an init failure, which may be provoked by misconfiguration or malicious manipulation of the ACPI interface, and can lead to a kernel crash, so administrators should consider it a high‑impact concern despite the low probability of exploitation. It is inferred that the attack vector would require local or privileged access to the system to influence ACPI initialization or CPU frequency changes.

Generated by OpenCVE AI on September 19, 2026 at 14:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to the latest stable release containing the fix for this issue
  • Reboot the system into the updated kernel to ensure the change takes effect
  • If an immediate kernel upgrade is not possible, disable CPU frequency scaling or the ACPI processor driver to prevent the notifier from being registered until a patch can be applied

Generated by OpenCVE AI on September 19, 2026 at 14:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-478

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Unregister cpufreq notifier on init failure acpi_processor_driver_init() registers the cpufreq policy notifier before registering the ACPI processor driver and setting up CPU hotplug state. If driver_register() or cpuhp_setup_state() fails, the error path only unregisters the ACPI processor driver and the idle driver. The cpufreq notifier remains registered even though initialization failed. Mirror the module exit path on the init failure path and unregister the cpufreq notifier when it has been registered.
Title ACPI: processor: Unregister cpufreq notifier on init failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:07.474Z

Reserved: 2026-09-11T19:38:34.807Z

Link: CVE-2026-90364

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:35.480

Modified: 2026-09-17T17:17:35.480

Link: CVE-2026-90364

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T14:15:17Z

Weaknesses
  • CWE-478

    Missing Default Case in Multiple Condition Expression