In the Linux kernel, the following vulnerability has been resolved:
cpufreq: intel_pstate: Fix crash during turbo disable
When the system is booted with kernel command line argument "nosmt" or "maxcpus" to limit the number of CPUs, disabling turbo via:
echo 1 > /sys/devices/system/cpu/intel_pstate/no_turbo
results in a crash:
PF: supervisor read access in kernel mode PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP PTI ... RIP: 0010:store_no_turbo+0x100/0x1f0 ...
This occurs because for_each_possible_cpu() returns CPUs even if they are not online. For those CPUs, all_cpu_data[] will be NULL. Since commit 973207ae3d7c ("cpufreq: intel_pstate: Rearrange max frequency updates handling code"), all_cpu_data[] is dereferenced even for CPUs which are not online, causing the NULL pointer dereference.
To fix that, pass CPU number to intel_pstate_update_max_freq() and use all_cpu_data[] for those CPUs for which there is a valid cpufreq policy.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel6.18-develUpgrade kernel6.18-headersUpgrade kernel6.18-debuginfoUpgrade kernel6.18Upgrade kernel-livepatch-6.18.20-20.229Upgrade kernel6.18-libbpfUpgrade kernel6.18-debuginfo-common-aarch64Upgrade kernel6.18-debuginfo-common-x86_64Upgrade kernel6.18-toolsUpgrade kernel6.18-tools-develUpgrade kernel6.18-modules-extraUpgrade python3-perf6.18-debuginfoUpgrade python3-perf6.18Upgrade kernel6.18-modules-extra-commonUpgrade perf6.18Upgrade bpftool6.18-debuginfoUpgrade kernel6.18-libbpf-develUpgrade kernel6.18-tools-debuginfoUpgrade kernel6.18-libbpf-staticUpgrade perf6.18-debuginfoUpgrade bpftool6.18Upgrade kernel6.18-libbpf-debuginfo | May 4, 2026 | Mar 25, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub