Out-of-Bounds Index Vulnerability in Linux Kernel Related to DVFS Handling
CVE-2026-98362

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-98362?

A vulnerability within the Linux kernel's clock driver affects its ability to handle DVFS index values accurately. The function dvfs_get_idx() may return an index that exceeds acceptable bounds if the SCP firmware is faulty or out-of-date. While negative indexes are rejected, excessively large indexes may pass unchecked, leading to the risk of interpreting invalid data as clock rates. This flaw can result in service stability issues, as the kernel may attempt to execute operations based on erroneous frequencies derived from these out-of-range indexes. This vulnerability was introduced in the original SCPI clock driver and has been addressed by validating index limits, preventing values greater than or equal to the operational performance points (opps) count from being processed.

Affected Version(s)

Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f < 6e3b55823da8ef0d99621efb422cc29f50d7f280

Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f < 7204095917aeaac89db7377c29a457351a19b076

Linux cd52c2a4b5c43631e429d06dce12e08b0cab477f < 0f89e2ac0e945da2ce798f6a61aebf9d291c2e0a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.