Description
In the Linux kernel, the following vulnerability has been resolved:

cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks

cpufreq_cpu_get() returns NULL when no cpufreq policy is associated with
the requested CPU, for example because the CPU is offline or the policy
has already been torn down. Both amd_pstate_power_supply_notifier() and
amd_pstate_profile_set() acquire a policy via cpufreq_cpu_get() and then
pass that pointer to amd_pstate_get_balanced_epp() and
amd_pstate_set_epp(), which dereference it unconditionally. A racing
CPU hotplug or driver teardown can therefore lead to a NULL pointer
dereference on either of these dynamic EPP paths.

The third cpufreq_cpu_get() caller in this file, amd_pstate_verify(),
already handles the NULL case. Bring the two new callers in line with
that pattern: return NOTIFY_OK from the power-supply notifier (matching
the other "nothing to do" exits) and -ENODEV from amd_pstate_profile_set()
(the usual cpufreq error for a missing CPU policy).

Found by code inspection; not tested on hardware.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability is a NULL pointer dereference in the Linux kernel’s AMD P-state cpufreq driver. When a CPU hot‑plug event or driver teardown removes the policy associated with a particular CPU, calls to cpufreq_cpu_get() can return NULL. The subsequent unguarded use of the returned pointer by amd_pstate_power_supply_notifier() and amd_pstate_set_epp() causes a kernel fault, likely leading to a crash and a system reboot. This results in a denial of service for the affected host. The flaw reflects a null pointer dereference weakness, which is in the category of CWE-476.

Affected Systems

Linux kernel installations prior to the commit that added the missing policy checks are vulnerable. The issue applies to all kernels that include the AMD P-state cpufreq driver without the patched guard. Because the kernel is the core of the operating system, all userspace processes run with the privileges of the kernel and are indirectly affected by a crash. No specific distribution or kernel release is listed, so all affected builds should be checked for the presence of the cited commit and updated accordingly.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation. The attack vector is inferred to be local or privileged, as the flaw is within kernel code and requires the ability to trigger a CPU hot‑plug or driver teardown event. The impact is significant—a crash—which is mitigated by applying the patch. Given the low EPSS and lack of public exploits, the overall risk is moderate but the cost of a system reboot can be high. The security community has not reported active exploits for this flaw to date.

Generated by OpenCVE AI on September 19, 2026 at 05:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that includes the patch fixing the NULL pointer dereference in amd_pstate.
  • If a timely kernel update is not possible, disable the AMD P-state driver (e.g., by setting module disable options or using kernel boot parameters such as "intel_pstate=disable" if applicable, or unload the module with modprobe -r amd_pstate).
  • As a temporary mitigation, avoid CPU hot‑plug operations while the issue exists by restricting hot‑plug or by keeping the CPU configuration static.

Generated by OpenCVE AI on September 19, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks cpufreq_cpu_get() returns NULL when no cpufreq policy is associated with the requested CPU, for example because the CPU is offline or the policy has already been torn down. Both amd_pstate_power_supply_notifier() and amd_pstate_profile_set() acquire a policy via cpufreq_cpu_get() and then pass that pointer to amd_pstate_get_balanced_epp() and amd_pstate_set_epp(), which dereference it unconditionally. A racing CPU hotplug or driver teardown can therefore lead to a NULL pointer dereference on either of these dynamic EPP paths. The third cpufreq_cpu_get() caller in this file, amd_pstate_verify(), already handles the NULL case. Bring the two new callers in line with that pattern: return NOTIFY_OK from the power-supply notifier (matching the other "nothing to do" exits) and -ENODEV from amd_pstate_profile_set() (the usual cpufreq error for a missing CPU policy). Found by code inspection; not tested on hardware.
Title cpufreq/amd-pstate: handle missing policy in dynamic EPP callbacks
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:10:07.957Z

Reserved: 2026-09-16T12:21:13.871Z

Link: CVE-2026-92492

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:51.340

Modified: 2026-09-17T17:17:51.340

Link: CVE-2026-92492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T11:15:13Z

Weaknesses